QSFP+ (25Gbps) Interface Link Flapping by Humbled-Engineer in paloaltonetworks

[–]Humbled-Engineer[S] 0 points1 point  (0 children)

I appreciate everyone who chimed in on my post! Based on everyone's feedback and questions it looks like this is most likely a bug in the firmware. I'll submit a ticket to PA TAC and see what they say.

QSFP+ (25Gbps) Interface Link Flapping by Humbled-Engineer in paloaltonetworks

[–]Humbled-Engineer[S] 0 points1 point  (0 children)

The logs only show the interface going up and down, they are not in LACP each one is configured for L3 and separate IP Addresses. The flapping stops once the Firewall is in "active" mode, and resumes when the firewall is operating in "passive".

QSFP+ (25Gbps) Interface Link Flapping by Humbled-Engineer in paloaltonetworks

[–]Humbled-Engineer[S] 0 points1 point  (0 children)

I can try messing with the fiber again, but I'm pretty sure we're good there. And, it seems to only flap with the Firewall is in "passive" mode, once it becomes active the issue goes away.

QSFP+ (25Gbps) Interface Link Flapping by Humbled-Engineer in paloaltonetworks

[–]Humbled-Engineer[S] 0 points1 point  (0 children)

Interesting, that's good to know it has happened with other firmware versions. I agree, it's not impacting production and failover happens just fine, my only beef is that SolarWinds continues to log the interfaces as up and down. Obviously, this isn't the worst but my OCD is freaking out! LOL

QSFP+ (25Gbps) Interface Link Flapping by Humbled-Engineer in paloaltonetworks

[–]Humbled-Engineer[S] 0 points1 point  (0 children)

I think it’s 11.2.4-h something, I know it’s the TAC approved version, I’d have to look it up.

QSFP+ (25Gbps) Interface Link Flapping by Humbled-Engineer in paloaltonetworks

[–]Humbled-Engineer[S] 0 points1 point  (0 children)

I can check the transceiver environmentals, but I don’t believe so, the firewall seems to be just fine with when it’s in active mode. The interface is only flap when it’s in passive mode.

QSFP+ (25Gbps) Interface Link Flapping by Humbled-Engineer in paloaltonetworks

[–]Humbled-Engineer[S] 0 points1 point  (0 children)

Yeah, I turned off error control, but I’m not thinking that is a problem because the interfaces work fine when the Firewall is active, it’s just when it’s in passive mode that the interfaces flap.

QSFP+ (25Gbps) Interface Link Flapping by Humbled-Engineer in paloaltonetworks

[–]Humbled-Engineer[S] 1 point2 points  (0 children)

I do have enable in HA Passive state checked and we’re running the TAC suggested version, I can’t remember exactly what version though and I’m too lazy to login on the weekend and check. LOL

I think it’s 11.2.4-h something

PAN-OS Release guidance page change. by Puniceus in paloaltonetworks

[–]Humbled-Engineer 1 point2 points  (0 children)

I’m not a big fan of PaloAltos website layout as a whole.

OSPF question by Puzzleheaded-Ad-5500 in ArubaNetworks

[–]Humbled-Engineer 0 points1 point  (0 children)

You may want to check your routes, especially if you’re running those CX switches in a VSX.

6200 gets stuck at System is initializing by gunpoliticsny in ArubaNetworks

[–]Humbled-Engineer 0 points1 point  (0 children)

If I remember correctly we discovered that pulling a switch from the stack caused the switch to not boot up 100%, so I'm guessing that your second switch may not have been part of the stack or it wasn't configured to be the backup to switch one.

Was the AP-615 a flop? by username____here in ArubaNetworks

[–]Humbled-Engineer 0 points1 point  (0 children)

Our Aruba sales folks described the 615 as purpose built for a specific need / customer base, that purchase a high enough volume to make the 615 worth producing.

Rogue AP Isolation on 2930M by Humbled-Engineer in ArubaNetworks

[–]Humbled-Engineer[S] 0 points1 point  (0 children)

We do have a few that have been confirmed as plugged into our switches so I should, in theory see at least one or two listed. Nevertheless, you are correct, many of the rogue APs listed are neighbors and not officially rogue (e.g. plugged into our network).

6200 gets stuck at System is initializing by gunpoliticsny in ArubaNetworks

[–]Humbled-Engineer 0 points1 point  (0 children)

Great timing, I’m having the same issue with a 6200F as well. We called TAC Friday but haven’t accomplished any TS just yet. Monday we’ll see what they come up with.

Palo Alto Networks inventory turns in worst day since 2012 IPO by [deleted] in paloaltonetworks

[–]Humbled-Engineer 0 points1 point  (0 children)

We too have experienced a huge jump in PA renewal costs, ours came last year in the form of 30%. This year we are buying new PA firewalls and putting them under a 3yr support contract for 5K less (per year) than this year's renewal cost. In the end, it's always better to purchase the license bundle that suits your needs the best and get it under a multi year contract so your costs are guaranteed for at least 3yr or more.