HA interfaces not receiving traffic for Palo Alto Networks

Vendor

Palo Alto Networks

Description

A Palo Alto Networks firewall can have up to three HA interfaces. They should all be receiving traffic at all times. If one stops receiving traffic, Indeni will alert.

Remediation Steps

Determine why traffic is not being received on the listed ports. Make sure the keep-alive is enabled on HA2. Review https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/high-availability/configure-active-passive-ha as well.

How does this work?

This alert logs into the Palo Alto Networks firewall through SSH and retrieves the status of all network interfaces. In that output, it looks for the number of packets received through the interface.

Why is this important?

This alert logs into the Palo Alto Networks firewall through SSH and retrieves the status of all network interfaces. In that output, it looks for the number of packets received through the interface.

Without Indeni how would you find this?

The traffic statistics of network interfaces can be retrieved through SNMP in newer versions of PAN-OS (7.x).


View Source Code