<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA Active / Active without Virtual IP in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-active-active-without-virtual-ip/m-p/594154#M3550</link>
    <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/259627"&gt;@Edsnow&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For&amp;nbsp;&lt;SPAN&gt;route-based redundancy:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In a Layer 3 interface deployment and active/active HA configuration, the firewalls are connected to routers, not switches. The firewalls use dynamic routing protocols to determine the best path (asymmetric route) and to load share between the HA pair. In such a scenario, no floating IP addresses are necessary. If a link, monitored path, or firewall fails, or if Bidirectional Forwarding Detection (BFD) detects a link failure, the routing protocol (RIP, OSPF, or BGP) handles the rerouting of traffic to the functioning firewall. You configure each firewall interface with a unique IP address. The IP addresses remain local to the firewall where they are configured; they do not move between devices when a firewall fail&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Aug 2024 15:15:30 GMT</pubDate>
    <dc:creator>Alejandro_Hernandez</dc:creator>
    <dc:date>2024-08-06T15:15:30Z</dc:date>
    <item>
      <title>PA Active / Active without Virtual IP</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-active-active-without-virtual-ip/m-p/594021#M3542</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In PA active / active configuration, what will happen if there is no virtual address is configured.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am seeing there are two ISP configured in each one in each firewall. Is it right way to configure it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 15:38:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-active-active-without-virtual-ip/m-p/594021#M3542</guid>
      <dc:creator>Edsnow</dc:creator>
      <dc:date>2024-08-05T15:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: PA Active / Active without Virtual IP</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-active-active-without-virtual-ip/m-p/594024#M3544</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/259627"&gt;@Edsnow&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So depends of use cases&lt;/P&gt;
&lt;P&gt;You will use the following guide with the use cases&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/set-up-activeactive-ha/determine-your-activeactive-use-case" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/set-up-activeactive-ha/determine-your-activeactive-use-case&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 16:25:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-active-active-without-virtual-ip/m-p/594024#M3544</guid>
      <dc:creator>Alejandro_Hernandez</dc:creator>
      <dc:date>2024-08-05T16:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: PA Active / Active without Virtual IP</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-active-active-without-virtual-ip/m-p/594084#M3548</link>
      <description>&lt;P&gt;Hi Alenjandro,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the reply,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case if,I choose to Active/active with route-based redundancy, Where the routing decision will be made. In router or Firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 05:27:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-active-active-without-virtual-ip/m-p/594084#M3548</guid>
      <dc:creator>Edsnow</dc:creator>
      <dc:date>2024-08-06T05:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: PA Active / Active without Virtual IP</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-active-active-without-virtual-ip/m-p/594154#M3550</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/259627"&gt;@Edsnow&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For&amp;nbsp;&lt;SPAN&gt;route-based redundancy:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In a Layer 3 interface deployment and active/active HA configuration, the firewalls are connected to routers, not switches. The firewalls use dynamic routing protocols to determine the best path (asymmetric route) and to load share between the HA pair. In such a scenario, no floating IP addresses are necessary. If a link, monitored path, or firewall fails, or if Bidirectional Forwarding Detection (BFD) detects a link failure, the routing protocol (RIP, OSPF, or BGP) handles the rerouting of traffic to the functioning firewall. You configure each firewall interface with a unique IP address. The IP addresses remain local to the firewall where they are configured; they do not move between devices when a firewall fail&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 15:15:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-active-active-without-virtual-ip/m-p/594154#M3550</guid>
      <dc:creator>Alejandro_Hernandez</dc:creator>
      <dc:date>2024-08-06T15:15:30Z</dc:date>
    </item>
  </channel>
</rss>

