Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A security engineer is performing troubleshooting on a Palo Alto Networks firewall in an active/passive High Availability (HA) configuration. The passive firewall unexpectedly transitions to a non-functional state, and the active firewall remains active, but it fails to synchronize session information to the passive unit. Upon investigation, the passive firewall shows 'link-state-monitoring' as 'down' for a critical interface. Which interface-specific setting is most likely misconfigured or missing on the passive firewall?

  1. ALink State Group
  2. BVirtual Router assignment
  3. CHA Peer IP address
  4. DHA Path Monitoring
Show answer & explanation

Correct answer: A. Link State Group

Link-state monitoring in HA relies on Link State Groups. If a critical interface's link state is reported as 'down' and causes a non-functional state, it indicates that the interface is part of a Link State Group, and the group's thresholds or the interface's membership in the group might be misconfigured on the passive firewall.

Why the other options are wrong

  • B. Virtual Router assignment is for routing, not directly for link-state monitoring itself.
  • C. HA Peer IP address is for HA communication, not directly for link-state monitoring of data interfaces.
  • D. HA Path Monitoring monitors end-to-end paths (e.g., to a gateway), not directly the link state of a local interface itself, although it can trigger similar HA actions.

HA Link State Group

A High Availability feature that monitors the operational status of grouped interfaces and can trigger state changes (e.g., non-functional, failover) if a defined threshold of links go down.

  • Ensures the firewall only stays active if critical interfaces are up.
  • Configured under Network > High Availability > Link State Group.
  • Interfaces are added to a group, and a threshold is set.

Memory trick: Link State Groups keep the heart of HA beating.

More Troubleshoot questions