<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 3 node cluster or HA in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/3-node-cluster-or-ha/m-p/1260469#M7053</link>
    <description>&lt;P&gt;Its the ask from the client that they need to have higher redundancy&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2026 14:10:42 GMT</pubDate>
    <dc:creator>M.Sridharan</dc:creator>
    <dc:date>2026-07-30T14:10:42Z</dc:date>
    <item>
      <title>3 node cluster or HA</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/3-node-cluster-or-ha/m-p/1260453#M7049</link>
      <description>&lt;P&gt;Hi community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am setting up a palo alto firewalls for&amp;nbsp; a customer and they need it as 3 nodes. they are going to be placed in three different buidling inside the same campus.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have gone through the documents and seeing that clustering is the only option as it is 3 in number.&lt;/P&gt;
&lt;P&gt;I want to know is there any way that i can make this into HA of 3 nodes with their HA1 and HA2 being switched using LAyer 2 extensions across these buildings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also if i want to form a cluster, only session synchronisation is achieved via HA4 links, won't the config and control plane activities wont be synced across the cluster members via the Group master ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;OR config sync for cluster can be achieved only via panorama deployment ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly shed some light on this to get me decide things up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 10:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/3-node-cluster-or-ha/m-p/1260453#M7049</guid>
      <dc:creator>M.Sridharan</dc:creator>
      <dc:date>2026-07-30T10:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: 3 node cluster or HA</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/3-node-cluster-or-ha/m-p/1260465#M7051</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/409088421"&gt;@M.Sridharan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I'm confused by the business requirements here. Why do you need three firewalls simply because you have three buildings across your campus? What's the rationale there?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 14:03:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/3-node-cluster-or-ha/m-p/1260465#M7051</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2026-07-30T14:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: 3 node cluster or HA</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/3-node-cluster-or-ha/m-p/1260469#M7053</link>
      <description>&lt;P&gt;Its the ask from the client that they need to have higher redundancy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 14:10:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/3-node-cluster-or-ha/m-p/1260469#M7053</guid>
      <dc:creator>M.Sridharan</dc:creator>
      <dc:date>2026-07-30T14:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: 3 node cluster or HA</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/3-node-cluster-or-ha/m-p/1260478#M7056</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/409088421"&gt;@M.Sridharan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Unless this environment has multiple active DCs in each building, or an actual active/standby DC, this rarely actually makes sense. I don't know what type of environment you're working with here, but it's just pretty abnormal that someone with this sort of setup would be outsourcing its configuration to someone who hasn't set it up before. You'll also have limited hardware options that actually support this, so there's quite a lot of groundwork to do to verify that this actually makes sense for the client and they're prepared for the cost of what they're asking for.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would&amp;nbsp;&lt;EM&gt;highly&amp;nbsp;&lt;/EM&gt;recommend reading up on clustering and the limitations that it brings, alongside asking a ton of environment questions to verify that it is the right choice. Depending on the environment, introducing it properly and actually accomplishing increased redundancy can mean introducing a&amp;nbsp;&lt;EM&gt;lot&amp;nbsp;&lt;/EM&gt;more changes than just the firewall topology.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for your actual questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I want to know is there any way that i can make this into HA of 3 nodes with their HA1 and HA2 being switched using LAyer 2 extensions across these buildings.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;This is not at all how clustering works. Toss HA1 and HA2 out of your mind in a cluster, they are only relevant if you are making a cluster out of HA pairs.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also if i want to form a cluster, only session synchronisation is achieved via HA4 links, won't the config and control plane activities wont be synced across the cluster members via the Group master ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;As far as configuration goes, it's assumed that you are going to be using Panorama to keep things in sync. You can do it standalone if you have templating and automation in place to mirror things, but outside of Panorama or SCM you will need to ensure that the firewalls are actually sharing the required configuration manually.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;OR config sync for cluster can be achieved only via panorama deployment ?&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;You do not&amp;nbsp;&lt;EM&gt;need&amp;nbsp;&lt;/EM&gt;to use Panorama for a cluster, but it is&amp;nbsp;&lt;EM&gt;highly&amp;nbsp;&lt;/EM&gt;recommended and would be the 'standard' way to manage things. You can absolutely do it standalone, but you're going to want to have templating and automation already in place to ensure that the configuration between cluster members are actually in-sync.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 14:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/3-node-cluster-or-ha/m-p/1260478#M7056</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2026-07-30T14:58:27Z</dc:date>
    </item>
  </channel>
</rss>

