Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootEasy

A network administrator is troubleshooting an issue where users are unable to access internal resources after a recent firmware upgrade on a Palo Alto Networks firewall in an active/passive High Availability (HA) configuration. The passive firewall is showing as 'non-functional' in the HA status. Which of the following is the MOST likely cause for the passive firewall's state?

  1. AThe passive firewall is running a different software version than the active firewall.
  2. BThe passive firewall's management interface is incorrectly configured.
  3. CThe HA backup link is experiencing high latency.
  4. DThe HA control link is down.
Show answer & explanation

Correct answer: A. The passive firewall is running a different software version than the active firewall.

In an active/passive HA configuration, both firewalls must run the exact same software version to maintain a healthy HA state. A version mismatch will often prevent the passive firewall from becoming fully functional and can lead to a 'non-functional' state.

Why the other options are wrong

  • B. An incorrectly configured management interface might prevent access to the firewall, but wouldn't directly cause a 'non-functional' HA state related to a firmware upgrade.
  • C. High latency on the HA backup link can cause performance issues or failover delays, but is less likely to directly cause a 'non-functional' state due to a firmware upgrade.
  • D. A down HA control link would typically show a 'down' state for HA, but not necessarily 'non-functional' due to a firmware upgrade.

HA Version Mismatch

Palo Alto Networks firewalls in an HA pair must run the identical software version to ensure proper synchronization and functionality.

  • Required for active/passive and active/active HA.
  • Mismatched versions can lead to 'non-functional' or 'partial' states.
  • Always upgrade both devices to the same version.

Memory trick: High Availability needs Harmonic Alignment of versions.

More Troubleshoot questions