I have query about issue, we applying an update of an active-active ha we found that when we upgrade from version 9.1.14h1 to 10.0. 11h1 the secondary active device doesnt reintegrate to the ha and we get the status of Suspended (Non-functional loop detected), we disabled the ling group and the preemptive but still the same:
When does an HA node go into Suspended state due to Non-Functio... - Knowledge Base - Palo Alto Networks
Additionally the ha status widget changes every time we refresh it and the interfaces that process traffic are down, we did the downgrade and when we do it, the error does not appear and everything works properly.
For those who have experience in updating versions in Active-Active, both devices have to be updated in parallel? I can't get ahead of updating first the device Active-Secundary then device Active-Primary later?
I mention it for the logs I saw in ha_agent:
debug: ha_state_cfg_sync_allowed(src/ha_state_cfg.c:204): Group 11: other side doesn't have compatible version so don't send automatic config sync
HA Group 11: Peer device running a compatibile but different version 9.1.14-h1
Any comments is good.
A cluster with mismatching PANOS does not function properly. In an A/P environment that simply translates to the upgraded member being nonfunctional, but in an A/A the results may be a little more dramatic. It is best to upgrade both members at (nearly) the same time so normal HA functionality is assured