<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ION HA with dedicated controller port in Prisma SD-WAN Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/ion-ha-with-dedicated-controller-port/m-p/547003#M99</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66994"&gt;@Markus_B&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The possibility you explained with the switch will not face the issue because the drive with an HA-active state will continue its functioning. All my inputs are from experience. and HA logic is similar to VRRP here with Prisma-SDWAN.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2023 13:11:23 GMT</pubDate>
    <dc:creator>kn</dc:creator>
    <dc:date>2023-06-23T13:11:23Z</dc:date>
    <item>
      <title>ION HA with dedicated controller port</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/ion-ha-with-dedicated-controller-port/m-p/546865#M96</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we recently re-IP'd a set of two ION3000s in an HA group and saw that site losing connectivity at every single step. That got me thinking - these IONs have two controller ports, one of which is completely unused. Can we configure that empty controller port on both IONs to be in some none-routable /30 subnet and connect the IONs directly to each other? We're doing essentially that on all our panOS firewalls already and it works great.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 14:10:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/ion-ha-with-dedicated-controller-port/m-p/546865#M96</guid>
      <dc:creator>Markus_B</dc:creator>
      <dc:date>2023-06-22T14:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: ION HA with dedicated controller port</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/ion-ha-with-dedicated-controller-port/m-p/546953#M97</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66994"&gt;@Markus_B&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In-person, I don't think connecting the ION controller2 interfaces back to back is a smart idea. When the active ION is powered off, the backup ION cannot become operational since its HA-control port (controller2) is likewise shut down.&lt;BR /&gt;You may run a fast test on this behavior to confirm the above assertion.&lt;BR /&gt;&lt;BR /&gt;-kn&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 04:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/ion-ha-with-dedicated-controller-port/m-p/546953#M97</guid>
      <dc:creator>kn</dc:creator>
      <dc:date>2023-06-23T04:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: ION HA with dedicated controller port</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/ion-ha-with-dedicated-controller-port/m-p/546998#M98</link>
      <description>&lt;P&gt;Thanks for your reply, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223283"&gt;@kn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;unfortunately, I don't have any lab units to test this with. I also haven't been able to find any technical details on how HA is designed, so I can only speculate. However, let me think your comment a bit further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're essentially saying, that an ION in an operational HA-group and passive state will refuse to ever become active, if the port configured for HA-sync is physically down. That would mean, that if I have the controller ports on a physically separate management network and the corresponding switch fails (or the cable gets damaged or unplugged), I lose HA completely. I would personally consider that questionable system design and be worried about deploying these IONs until an Engineer with Palo/Cloudgenix has a very good explanation on why that is. However I assume, that you're guessing as much as I am?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 12:53:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/ion-ha-with-dedicated-controller-port/m-p/546998#M98</guid>
      <dc:creator>Markus_B</dc:creator>
      <dc:date>2023-06-23T12:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: ION HA with dedicated controller port</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/ion-ha-with-dedicated-controller-port/m-p/547003#M99</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66994"&gt;@Markus_B&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The possibility you explained with the switch will not face the issue because the drive with an HA-active state will continue its functioning. All my inputs are from experience. and HA logic is similar to VRRP here with Prisma-SDWAN.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 13:11:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/ion-ha-with-dedicated-controller-port/m-p/547003#M99</guid>
      <dc:creator>kn</dc:creator>
      <dc:date>2023-06-23T13:11:23Z</dc:date>
    </item>
  </channel>
</rss>

