eG Monitoring
 

Measures reported by PanHAStatusTest

High availability (HA) is a configuration in which two firewalls are placed in a group and their configuration is synchronized to prevent a single point of failure on your network. A heartbeat connection between the firewall peers ensures seamless failover in the event that a peer goes down. Setting up two firewalls in an HA pair provides redundancy and allows you to ensure business continuity.

The Palo Alto firewalls can be deployed as high availability (HA ) pair with session and configuration synchronization to provide uninterrupted operation in any session. The high availability configuration always ensures that one of the two firewalls is available for maintaining the network traffic so that the downtime of the network is reduced considerably. The firewalls can be configured as stateful Active/Passive or Active/Active high availability pair.

If the high availability of the firewall is challenged, then the your environment may be rendered defenceless against unsavory virus attacks and unauthorized access, both of which can cause irreparable damage. Hence, to make sure that your environment stays protected 24X7x365 from network threats, it is necessary to monitor the high availability status of the Palo Alto Firewall. The PanHAStatusTest test exactly helps you in this regard.

By continuously monitoring the Palo Alto Firewall, this test reveals the high availability status of the firewall and the mode in which the firewall is configured for high availability.

Outputs of the test : One set of results for the firewall being monitored.

The measures made by this test are as follows:

Measurement Description Measurement Unit Interpretation
HA_status Indicates the high availability status of the firewall.   The numeric values that correspond to these states are as follows:

State Numeric value
Unknown 0
Active 1
Passive 2
Suspended 3
Initial 4
Non-functional 5
Active-primary 6
Active-secondary 7
Tentative 8

Note:

By default, this measure reports the above-mentioned States to indicate whether/not the high availability is enabled for the PaloAlto firewall . However, in the graph of this measure, the same will be represented using the numeric equivalents – 0 and 100 only.

HA_mode Indicates the mode in which the firewall is configured for high availability.   The numeric values that correspond to these states are as follows:

Mode Numeric value
Disabled 0
Active-Passive 1
Active-Active 2

Note:

By default, this measure reports the above-mentioned Modes to indicate in which mode the firewall is configured for high availability. However, in the graph of this measure, the same will be represented using the numeric equivalents – 0 and 2 only.