1. Palo Alto Networks PAN-OS® Administrator’s Guide 11.0: In the section on High Availability
it specifies the function of the HA links.
Reference: "HA Concepts > HA Links and Backup Links"
Content: "The HA2 link is a Layer 2 link that is used to synchronize sessions
forwarding tables
ARP tables
and IPsec SAs between the firewalls in an HA pair." This confirms the use of the HA2 link for SA synchronization.
2. Palo Alto Networks PAN-OS® Administrator’s Guide 11.0: The guide explicitly details which SAs are synchronized for stateful failover.
Reference: "High Availability > Set Up Active/Passive HA > Stateful Failover for IPsec Tunnels"
Content: "For stateful failover of IPsec tunnels
the firewall synchronizes only the Phase 2 SAs. The IKE (Phase 1) SA is not synchronized." This directly supports that only Phase 2 SAs are synchronized.