
Service the PA-7000 Series Firewall Hardware
STEP 7 |
Insert the network cables that you removed earlier.
For slot status information and troubleshooting, see the following sections:
PA-7000 Series Firewall Network Processing Card (NPC)
.
Replace PA-7000 Series Firewall NPC in a High Availability (HA) Configuration
When HA is configured on the firewall, the firewall is designed to allow the insertion of new
Network Processing Cards (NPCs) without causing a failover. This is accomplished by the system
not allowing a new card to come up in one chassis until an NPC is installed in the same slot on the
second chassis. The cards stay in a disabled state until you enable both cards simultaneously.
If an NPC fails on one of the chassis, that chassis changes to a non-functional state when in
active/passive mode or to a tentative state when in active/active mode. The chassis stays in
the failover state until a new NPC is installed and configured or until you remove or disable the
matching NPC in the functioning firewall. After the failed card is replaced and enabled, the chassis
comes up as passive (in active/passive configuration) or as active-secondary (in an active/active
configuration).
To identify the failed NPC, check the LEDs on the NPC or check the system logs. For example,
if slot 3 has a failed NPC in one of the chassis, the following error is displayed in the log:
Slot3
failure; moving to failure state
.
In the following procedure, the first seven steps are the same steps you follow for replacing an
NPC in a single chassis. The HA specific steps start at
. For images on replacing an NPC, see
Replace PA-7000 Series Firewall NPC in a Single Chassis
.
STEP 1 |
Verify the status of the NPC that is having a problem. You can do this from the web interface
or from the CLI. In the web interface, navigate to
Network
>
Interfaces
to view status for
each NPC slot. The system log also shows
slot <slot-number>failure; moving to
failure state
.
If the NPC failed due to a hardware problem, the status shows
Failure
. The NPC may also
have a configuration problem, in which case you should run the
commit force
command to
force a commit.
If the firewall with the failed NPC is the active firewall, ensure that you trigger a
failover before removing the NPC. For more information, see
PA-7000 Series Firewall Hardware Reference
168
©
2023 Palo Alto Networks, Inc.