<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP Address and MAC address in Active\Passice HA Mode in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-address-and-mac-address-in-active-passice-ha-mode/m-p/563701#M2030</link>
    <description>&lt;P&gt;Each firewall has it's own mac that it comes with from factory.&lt;/P&gt;
&lt;P&gt;When you enable HA then based on group number new virtual mac address is generated.&lt;/P&gt;
&lt;P&gt;This virtual mac address is then used by active firewall to reply to arp requests.&lt;/P&gt;
&lt;P&gt;If you fail over to secondary firewall then gratuitous arp is sent out by secondary firewall about mac address moving to other switchport and this secondary starts responding to arp requests using same virtual mac.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As virtual mac is generated based HA group number you never want to put 2 Palo HA clusters (4 firewalls) into same ethernet network with same group number. This will cause mac address conflict.&lt;/P&gt;</description>
    <pubDate>Tue, 31 Oct 2023 12:31:24 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-10-31T12:31:24Z</dc:date>
    <item>
      <title>IP Address and MAC address in Active\Passice HA Mode</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-address-and-mac-address-in-active-passice-ha-mode/m-p/563644#M2028</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does Active\Passive HA firewalls have same physical MAC address on Data plane Interfaces? I feel MAC address are unique and how come MAC address can be same on both firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does Virtual MAC addresses and floating IP's are used in Active\Passive HA mode? If used how they are configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 03:04:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-address-and-mac-address-in-active-passice-ha-mode/m-p/563644#M2028</guid>
      <dc:creator>srikarpuligandla</dc:creator>
      <dc:date>2023-10-31T03:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address and MAC address in Active\Passice HA Mode</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-address-and-mac-address-in-active-passice-ha-mode/m-p/563701#M2030</link>
      <description>&lt;P&gt;Each firewall has it's own mac that it comes with from factory.&lt;/P&gt;
&lt;P&gt;When you enable HA then based on group number new virtual mac address is generated.&lt;/P&gt;
&lt;P&gt;This virtual mac address is then used by active firewall to reply to arp requests.&lt;/P&gt;
&lt;P&gt;If you fail over to secondary firewall then gratuitous arp is sent out by secondary firewall about mac address moving to other switchport and this secondary starts responding to arp requests using same virtual mac.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As virtual mac is generated based HA group number you never want to put 2 Palo HA clusters (4 firewalls) into same ethernet network with same group number. This will cause mac address conflict.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 12:31:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-address-and-mac-address-in-active-passice-ha-mode/m-p/563701#M2030</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-10-31T12:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address and MAC address in Active\Passice HA Mode</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-address-and-mac-address-in-active-passice-ha-mode/m-p/563781#M2034</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;@&lt;STRONG&gt;Raido_Rattameister&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 21:59:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-address-and-mac-address-in-active-passice-ha-mode/m-p/563781#M2034</guid>
      <dc:creator>srikarpuligandla</dc:creator>
      <dc:date>2023-10-31T21:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address and MAC address in Active\Passice HA Mode</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-address-and-mac-address-in-active-passice-ha-mode/m-p/563881#M2035</link>
      <description>&lt;P&gt;As a side note if you use virtual firewalls in VMware then most likely you turn off virtual mac option because to use virtual mac you would need to configure vSwitches into promiscuous mode (very bad idea).&lt;/P&gt;
&lt;P&gt;As a result each HA firewall will have it's own mac.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Device &amp;gt; Setup &amp;gt; Management &amp;gt;&amp;nbsp;Use Hypervisor Assigned MAC Addresses&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 12:42:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-address-and-mac-address-in-active-passice-ha-mode/m-p/563881#M2035</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-01T12:42:55Z</dc:date>
    </item>
  </channel>
</rss>

