Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium
A security engineer is performing troubleshooting on a Palo Alto Networks firewall in an active/passive High Availability (HA) configuration. The passive firewall unexpectedly transitions to a non-functional state, and the active firewall remains active, but it fails to synchronize session information to the passive unit. Upon investigation, the passive firewall shows 'link-state-monitoring' as 'down' for a critical interface. Which interface-specific setting is most likely misconfigured or missing on the passive firewall?
- ALink State Group
- BVirtual Router assignment
- CHA Peer IP address
- DHA Path Monitoring
Show answer & explanationAnswer & explanation
Correct answer: A. Link State Group
Link-state monitoring in HA relies on Link State Groups. If a critical interface's link state is reported as 'down' and causes a non-functional state, it indicates that the interface is part of a Link State Group, and the group's thresholds or the interface's membership in the group might be misconfigured on the passive firewall.
Why the other options are wrong
- B. Virtual Router assignment is for routing, not directly for link-state monitoring itself.
- C. HA Peer IP address is for HA communication, not directly for link-state monitoring of data interfaces.
- D. HA Path Monitoring monitors end-to-end paths (e.g., to a gateway), not directly the link state of a local interface itself, although it can trigger similar HA actions.
HA Link State Group
A High Availability feature that monitors the operational status of grouped interfaces and can trigger state changes (e.g., non-functional, failover) if a defined threshold of links go down.
- Ensures the firewall only stays active if critical interfaces are up.
- Configured under Network > High Availability > Link State Group.
- Interfaces are added to a group, and a threshold is set.
Memory trick: Link State Groups keep the heart of HA beating.