Question 1
A financial institution is deploying Palo Alto Networks NGFWs in an Active/Passive HA pair. To ensure rapid failover, the security architect has configured path monitoring for critical upstream and downstream devices. The primary firewall's monitored IP addresses become unreachable, triggering a failover to the passive firewall. However, after the failover, users still cannot access the internet. A packet capture on the newly active firewall shows that it is not receiving any traffic on its external interface. Which configuration error is the most likely cause of this issue?
Answer and explanation
Correct answer: B
In an Active/Passive HA failover, the newly active firewall takes over the virtual MAC address and IP addresses of the interfaces. It sends a gratuitous ARP (GARP) request to update the ARP tables of adjacent network devices. If the upstream switch or router does not process this GARP correctly, it will continue sending traffic to the MAC address of the previously active firewall's physical port, causing traffic to be black-holed. This is a common real-world failover issue.