OCI Virtual Networking - Palo Alto/Fortinet/Checkpoint/F5 VM-Series in High Availability Mode Does Not Failover
(Doc ID 2850214.1)
Last updated on OCTOBER 27, 2023
Applies to:
Oracle Cloud Infrastructure Virtual Networking - Version N/A to N/AInformation in this document applies to any platform.
Symptoms
The Palo Alto (or CheckPoint, Fortinet, F5 etc.) VM-Series firewall in the Oracle Cloud Infrastructure (OCI) is configured for High Availability (HA) and it is not failing over when expected. This document is under constant development and addresses both devices - each will be referenced appropriately. In most cases, support for the specific device manufacturer should be engaged for official device support.
Device logs may show any of the following:
- Getting token failed with
- CheckPoint errors are logged to the $FWDIR/log/oracle_had.elg and will show errors attempting to reach the API server.
Cause
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Symptoms |
Cause |
Solution |