A network security engineer is deploying a Palo Alto Networks firewall in a high-availability (HA) active/passive configuration. The engineer wants to ensure that the passive firewall takes over seamlessly if the active firewall fails. Which of the following is a requirement for HA active/passive configuration?
For HA active/passive, both firewalls must be the same hardware model and run the same PAN-OS software version. This ensures that the passive firewall can take over without compatibility issues. If the models or software versions differ, the HA pair may not form, or failover may not work correctly. Identical hardware and software also ensure consistent performance and feature support. While some platforms allow mixed models in HA, it is not recommended and may not be supported. For seamless failover, identical configurations are essential.
Why this answer
For HA active/passive, both firewalls must be identical in hardware model and PAN-OS software version to ensure compatibility and seamless failover. The passive firewall synchronizes configuration from the active firewall, so security policies are the same. Each firewall needs a unique management IP for separate management.
Priority values are used for election but are not required to be higher on the active firewall. The passive firewall does not have a separate blocking policy.
Exam trap
The trap here is thinking that the active firewall must have a higher priority, but priority is only used for election and does not define the active/passive role.