<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama HA Two different Data Center in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-two-different-data-center/m-p/570308#M2049</link>
    <description>&lt;P&gt;I have some following Questions:&lt;/P&gt;
&lt;P&gt;As per M700 SFP+ ports eth1/2 and eth1/3 bundled called as Bond1 interface, in what use cases we use this bundle interface in Panorama, Is Data traffic [Communication between Managed firewalls and Panorama]. One of the use cases I could think off, if we want to achieve level redundancy to be achieved. Is that right understanding?&lt;/P&gt;
&lt;P&gt;However, if we go for M-300 as there is no interface redundancy available, what would the solution for M300 redundancy [interface level]&lt;/P&gt;</description>
    <pubDate>Tue, 19 Dec 2023 05:36:30 GMT</pubDate>
    <dc:creator>Ramakrishnan</dc:creator>
    <dc:date>2023-12-19T05:36:30Z</dc:date>
    <item>
      <title>Panorama HA Two different Data Center</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-two-different-data-center/m-p/570065#M2046</link>
      <description>&lt;P&gt;Dear Folks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to setup Panorma High availability&amp;nbsp; between two different data centers [Netherland-Germany] I have checked the latecny is allowed upto 1000 ms. I have some following doubts.&lt;/P&gt;
&lt;P&gt;1. since these DC's running&amp;nbsp; different Ip address spce so for HA communication between these peers have two different Ip address, is not an constrains? As long as we have reachbility[L3/L4 level] will it work?&lt;/P&gt;
&lt;P&gt;2. since both peers are geographically seperated is there any nessasity to use SFP+ ports? that too PA has eth2/3 are in LAG ports[Viz M700 appliance]&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. As per admin guide, peer communication on MGT port then what is the purpose of Eth1/1 port, how do we configure dedicated HA for panorama&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 14:10:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-two-different-data-center/m-p/570065#M2046</guid>
      <dc:creator>Ramakrishnan</dc:creator>
      <dc:date>2023-12-15T14:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama HA Two different Data Center</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-two-different-data-center/m-p/570308#M2049</link>
      <description>&lt;P&gt;I have some following Questions:&lt;/P&gt;
&lt;P&gt;As per M700 SFP+ ports eth1/2 and eth1/3 bundled called as Bond1 interface, in what use cases we use this bundle interface in Panorama, Is Data traffic [Communication between Managed firewalls and Panorama]. One of the use cases I could think off, if we want to achieve level redundancy to be achieved. Is that right understanding?&lt;/P&gt;
&lt;P&gt;However, if we go for M-300 as there is no interface redundancy available, what would the solution for M300 redundancy [interface level]&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 05:36:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-two-different-data-center/m-p/570308#M2049</guid>
      <dc:creator>Ramakrishnan</dc:creator>
      <dc:date>2023-12-19T05:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama HA Two different Data Center</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-two-different-data-center/m-p/570335#M2051</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="username"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/178856" target="_self" aria-label="View Profile of Ramakrishnan"&gt;Ramakrishnan&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I have no idea if HA will work over 2 separate sites however, I can advise that you will need to add a variable template to the interfaces of each firewall as 'I would assume' these will be 2 different VLAN's (Unless you utilise OTV?), different internet addresses and a possible DMZ in there too. Please see below a guide to Templates.&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/panorama-web-interface/panorama-templates/panorama-templates-template-variable" target="_blank"&gt;Panorama &amp;gt; Templates &amp;gt; Template Variables (paloaltonetworks.com)&lt;/A&gt;&lt;BR /&gt;On a side note, Have you thought of utilising BGP routing and adding it to an internal routing protocol? Maybe you could go with an Active/Active set up or Active/Standby but the latency might be a bit much for those in the other country.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 12:48:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-two-different-data-center/m-p/570335#M2051</guid>
      <dc:creator>Kevin_Pearson</dc:creator>
      <dc:date>2023-12-19T12:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama HA Two different Data Center</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-two-different-data-center/m-p/570368#M2052</link>
      <description>&lt;P&gt;&lt;EM&gt;The HA peers use the management (MGT) interface to synchronize the configuration elements pushed&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;to the managed firewalls, Log Collectors, and WildFire appliances and appliance clusters to&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;maintain state information. Typically, Panorama HA peers are geographically located in different&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;sites, so you need to make sure that the MGT interface IP address assigned to each peer is&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;routable through your network&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;What is the use of Ether1 ports for log collection..?&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 18:56:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-two-different-data-center/m-p/570368#M2052</guid>
      <dc:creator>Ramakrishnan</dc:creator>
      <dc:date>2023-12-19T18:56:24Z</dc:date>
    </item>
  </channel>
</rss>

