<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HA Configuration with network provider router in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-configuration-with-network-provider-router/m-p/513713#M345</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case where I haven't switch between network provider router and our cluster of Palo Alto (Active/Passive), only a cable between router (eth1) and Eth1 of Active firewall, if the active FW is broken, the communication will be cut or not ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the best design to connect a sigle router of network operator to our FW cluster if we can dedicated a switch between router and FW ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JeromeC_0-1662024189356.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43626i49D44BB46658E26F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JeromeC_0-1662024189356.png" alt="JeromeC_0-1662024189356.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Sep 2022 09:24:57 GMT</pubDate>
    <dc:creator>JeromeC</dc:creator>
    <dc:date>2022-09-01T09:24:57Z</dc:date>
    <item>
      <title>HA Configuration with network provider router</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-configuration-with-network-provider-router/m-p/513713#M345</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case where I haven't switch between network provider router and our cluster of Palo Alto (Active/Passive), only a cable between router (eth1) and Eth1 of Active firewall, if the active FW is broken, the communication will be cut or not ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the best design to connect a sigle router of network operator to our FW cluster if we can dedicated a switch between router and FW ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JeromeC_0-1662024189356.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43626i49D44BB46658E26F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JeromeC_0-1662024189356.png" alt="JeromeC_0-1662024189356.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 09:24:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-configuration-with-network-provider-router/m-p/513713#M345</guid>
      <dc:creator>JeromeC</dc:creator>
      <dc:date>2022-09-01T09:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: HA Configuration with network provider router</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-configuration-with-network-provider-router/m-p/513772#M349</link>
      <description>&lt;P&gt;Yes, if the active PA fails the network will be cut off. You need a switch to link the active and passive external interfaces to the network provider router. Or get the network provider to bridge 2 ports together on their router.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;You show that your active/passive are connected to a VLAN on the internal network. Another possibility would be to create another VLAN on your existing internal switch and use that VLAN to bridge the active/passive external interfaces to the network provider router. If you are extremely short on switch ports you could even put the internal and external VLANs on the same physical ports (one switchport to each PA) and the external VLAN to the network provider.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 18:50:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-configuration-with-network-provider-router/m-p/513772#M349</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-09-01T18:50:20Z</dc:date>
    </item>
  </channel>
</rss>

