<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto IPV6 configuration for firewalls running in active-active HA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/443680#M100246</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a customer planning to enable IPV6 firewalling in their current&amp;nbsp; data center firewalls. The firewalls are currently running in active-active HA mode. I have the below queries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. When I configure IPV6 address on the interfaces, is there any possibility that the HA will break or it will have flaps?.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;When I configure floating IPV6 addresses on the firewalls, is there any possibility that the HA will break or it will have flaps?.&lt;/P&gt;&lt;P&gt;3. Is it mandatory to configure IPV6 addresses on the HA interfaces (like HA1,HA2 and HA3) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly advise&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Shabeeb&lt;/P&gt;</description>
    <pubDate>Wed, 27 Oct 2021 04:34:46 GMT</pubDate>
    <dc:creator>shabeeb</dc:creator>
    <dc:date>2021-10-27T04:34:46Z</dc:date>
    <item>
      <title>Palo Alto IPV6 configuration for firewalls running in active-active HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/443680#M100246</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a customer planning to enable IPV6 firewalling in their current&amp;nbsp; data center firewalls. The firewalls are currently running in active-active HA mode. I have the below queries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. When I configure IPV6 address on the interfaces, is there any possibility that the HA will break or it will have flaps?.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;When I configure floating IPV6 addresses on the firewalls, is there any possibility that the HA will break or it will have flaps?.&lt;/P&gt;&lt;P&gt;3. Is it mandatory to configure IPV6 addresses on the HA interfaces (like HA1,HA2 and HA3) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly advise&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Shabeeb&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 04:34:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/443680#M100246</guid>
      <dc:creator>shabeeb</dc:creator>
      <dc:date>2021-10-27T04:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto IPV6 configuration for firewalls running in active-active HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/443689#M100247</link>
      <description>&lt;P&gt;Thank you for posting questions&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75862"&gt;@shabeeb&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have enabled IPv6 in a few Data Centers and Firewalls are running dual stack. During actual configuration as well as post operation we did not come across any flapping or anything similar related to HA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I did not come across this issue and I believe enabling IPv6 on interface is safe and will not cause HA issue.&lt;/P&gt;&lt;P&gt;2. This operation should not cause an issue.&lt;/P&gt;&lt;P&gt;3. It is not mandatory to enabled IPv6 on HA interfaces. Your customer can keep using existing IPv4 HA configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 05:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/443689#M100247</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-27T05:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto IPV6 configuration for firewalls running in active-active HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/443748#M100253</link>
      <description>&lt;P&gt;Hello Pavel,&lt;/P&gt;&lt;P&gt;So only thing what we need to do is to configure the interfaces, floating IP address field of active-active HA and routing right. In your config you have one floating IP or two IPs?.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Shabeeb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 10:52:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/443748#M100253</guid>
      <dc:creator>shabeeb</dc:creator>
      <dc:date>2021-10-27T10:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto IPV6 configuration for firewalls running in active-active HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/443995#M100282</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;To ping to link-local addresses, you MUST specify the name of the output interface (because theoretically the same link-local address can appear behind different physical interfaces.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 07:15:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/443995#M100282</guid>
      <dc:creator>MichaelBryant</dc:creator>
      <dc:date>2021-10-28T07:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto IPV6 configuration for firewalls running in active-active HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/444077#M100290</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75862"&gt;@shabeeb&lt;/a&gt;&amp;nbsp; and sorry for late respnse.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, this is correct statement:&amp;nbsp;only thing what we need to do is to configure the interfaces, floating IP address field of active-active HA and routing.&lt;/P&gt;&lt;P&gt;Regarding floating IP address, only 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 13:23:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-ipv6-configuration-for-firewalls-running-in-active/m-p/444077#M100290</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-28T13:23:51Z</dc:date>
    </item>
  </channel>
</rss>

