<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Passive Failover in AWS in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/active-passive-failover-in-aws/m-p/1254351#M2460</link>
    <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;I am trying to configure Active-Passive (A/P) HA failover for Palo Alto VM-Series firewalls in AWS.&lt;/P&gt;&lt;P&gt;I have completed the HA configuration and updated the required IAM roles and permissions. Currently, the setup is partially working as expected:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Primary Public IP (EIP) successfully moves from Passive ENI to Active ENI during failover.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Route tables are also getting updated correctly after failover.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Traffic connectivity is working fine after failover.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;However, I am facing an issue when using multiple UNTRUST interfaces.&lt;/P&gt;&lt;P&gt;Scenario:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;I created additional UNTRUST NICs/ENIs.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Assigned separate Public IPs/EIPs to those ENIs for hosting different applications/services.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;During failover, only the first UNTRUST interface Public IP moves to the Active firewall.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The additional UNTRUST ENI Public IPs are not moving to the Active instance.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Requirement:&lt;BR /&gt;I need multiple UNTRUST NICs, each with its own Public IP/EIP, and all those EIPs should fail over automatically to the Active firewall during HA failover.&lt;/P&gt;&lt;P&gt;Current Environment:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;PAN-OS Version: 12.1.4-h5&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;AWS Plugin Version: 6.1.2-h1&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Has anyone implemented a similar design or faced this issue before? Any guidance or recommended configuration changes would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you in advance for your support.&lt;/P&gt;</description>
    <pubDate>Wed, 20 May 2026 05:26:44 GMT</pubDate>
    <dc:creator>haider.rangwala</dc:creator>
    <dc:date>2026-05-20T05:26:44Z</dc:date>
    <item>
      <title>Active Passive Failover in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/active-passive-failover-in-aws/m-p/1254351#M2460</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;I am trying to configure Active-Passive (A/P) HA failover for Palo Alto VM-Series firewalls in AWS.&lt;/P&gt;&lt;P&gt;I have completed the HA configuration and updated the required IAM roles and permissions. Currently, the setup is partially working as expected:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Primary Public IP (EIP) successfully moves from Passive ENI to Active ENI during failover.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Route tables are also getting updated correctly after failover.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Traffic connectivity is working fine after failover.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;However, I am facing an issue when using multiple UNTRUST interfaces.&lt;/P&gt;&lt;P&gt;Scenario:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;I created additional UNTRUST NICs/ENIs.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Assigned separate Public IPs/EIPs to those ENIs for hosting different applications/services.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;During failover, only the first UNTRUST interface Public IP moves to the Active firewall.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The additional UNTRUST ENI Public IPs are not moving to the Active instance.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Requirement:&lt;BR /&gt;I need multiple UNTRUST NICs, each with its own Public IP/EIP, and all those EIPs should fail over automatically to the Active firewall during HA failover.&lt;/P&gt;&lt;P&gt;Current Environment:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;PAN-OS Version: 12.1.4-h5&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;AWS Plugin Version: 6.1.2-h1&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Has anyone implemented a similar design or faced this issue before? Any guidance or recommended configuration changes would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you in advance for your support.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 05:26:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/active-passive-failover-in-aws/m-p/1254351#M2460</guid>
      <dc:creator>haider.rangwala</dc:creator>
      <dc:date>2026-05-20T05:26:44Z</dc:date>
    </item>
  </channel>
</rss>

