Next-Generation Firewall
HA Communications
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
-
-
-
-
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
HA Communications
Configure HA links for HA pairs or HA clusters.
- Device > High Availability > HA Communications
To configure HA links for HA pairs or HA clustering,
select DeviceHigh
AvailabilityHA Communications.
HA Links | Description |
---|---|
Control Link (HA1)/Control Link (HA1 Backup) | The firewalls in an HA pair use HA links ![]() For firewalls that don't have a dedicated HA port, such as the PA-220 firewall, you should
configure the management port for the Control Link HA connection and
a data port interface configured with type HA for the Control Link
HA1 Backup connection. Because the management port is used in this
case, there is no need to enable the Heartbeat Backup option because
the heartbeat backups will already occur through the management
interface connection. On the VM-Series firewall
in AWS, the management port is used as the HA1 link. When using a data port for the HA control link,
keep in mind that because the control messages have to communicate from
the dataplane to the management plane, if a failure occurs in the
dataplane, peers cannot communicate HA control link information
and a failover will occur. It is best to use the dedicated HA ports,
or on firewalls that do not have a dedicated HA port, use the management
port. |
Control Link (HA1)/Control Link (HA1 Backup) | Specify the following settings for the primary and backup HA control links when you configure Active/Passive
HA or configure Active/Active
HA:
|
Data Link (HA2) When an HA2 backup
link is configured, failover to the backup link will occur if there
is a physical link failure. With the HA2 keep-alive option enabled,
the failover will also occur if the HA keep-alive messages fail based
on the defined threshold. | Specify the following settings for the primary and backup data link when you configure Active/Passive
HA or configure Active/Active
HA:
|
| |
Clustering Links | When you configure HA clustering,
configure settings for HA4 links, which are dedicated HA cluster
links that synchronize session state among all cluster members
having the same cluster ID. The HA4 link between cluster members
detects connectivity failures between cluster members.
Configure HA4
Backup settings:
|