3.3 Ensure 'Passive Link State' and 'Preemptive' are configured appropriately - Election Setings

Information

Set the Passive Link State to auto, and uncheck the Preemptive option to disable it.
Rationale:
Simultaneously enabling the 'Preemptive' option and setting the 'Passive Link State' option to 'Shutdown' could cause a 'preemptive loop' if Link and Path Monitoring are both configured. This will negatively impact the availability of the firewall and network services, should a monitored failure occur.

Solution

To set Active/Passive Settings correctly:
Navigate to Device > High Availability > General > Active/Passive Settings.
Set Passive Link State to auto.
To set Election Settings correctly:
Navigate to Device > High Availability > Election Settings.
Set Preemptive to be disabled.
Impact:
Incorrectly configuring this setting will adversely affect availability, rather than positively affect it.

Default Value:
Not Configured

See Also

https://workbench.cisecurity.org/files/2104

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|11, CSCv7|11

Plugin: Palo_Alto

Control ID: 24bac9b90b2a580f765c7a378edf4e514e99803d4c3c35c776d6816a21b86bfe