<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How Palo alto HA and Cisco HSRP work together ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449655#M100959</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; , Thank you for your reply.&lt;/P&gt;&lt;P&gt;May I know what you have explained is same for both cisco catalyst and cisco nexus switches ?&lt;/P&gt;&lt;P&gt;Could also share if there is any document ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Nov 2021 14:00:47 GMT</pubDate>
    <dc:creator>perumalj</dc:creator>
    <dc:date>2021-11-26T14:00:47Z</dc:date>
    <item>
      <title>How Palo alto HA and Cisco HSRP work together ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449641#M100957</link>
      <description>&lt;P&gt;How Palo alto HA and Cisco HSRP work together ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example&amp;nbsp;&lt;/P&gt;&lt;P&gt;===========&lt;/P&gt;&lt;P&gt;Here Palo alto HA is upstream devices ( lets consider PA1 and PA2 are in HA setup).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco Switches are catalyst 6509 or nexus 5 or 6K ( SW1 and SW2)&lt;/P&gt;&lt;P&gt;SW1 is connected to PA 1 and SW2 is connected to PA2&amp;nbsp;&lt;/P&gt;&lt;P&gt;in SW1 and SW2 HSRP is configured to maintain gateway high availability for both upstream ( PA firewalls) and downstream( end hosts)&lt;/P&gt;&lt;P&gt;Static routing is configured between switches and upstream Devices( PA firewalls). As per the routing , if there is any traffic coming from end hosts will be forwarded to the upstream( PA active firewall). likewise , for the return traffic from the firewall will be forwarded to active switch using HSRP virtual IP address and Mac address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if we do manual HA failover between PA firewalls for some reasons and make PA2 now active but still going to keep SW1 active for HSRP like below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SW1( active for HSRP) ------&amp;gt;PA1 ( standby)&lt;/P&gt;&lt;P&gt;SW2( standby for HSRP)-----&amp;gt;PA2(Active)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. in this case how traffic flow would be ? whether it would create any impact to the traffic flow&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;2. Do we also need to do HSRP failover between switches when we do HA failover between PA firewalls ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly provide your suggestion on this&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 11:36:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449641#M100957</guid>
      <dc:creator>perumalj</dc:creator>
      <dc:date>2021-11-26T11:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo alto HA and Cisco HSRP work together ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449650#M100958</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197203"&gt;@perumalj&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no need to change HSRP priority to make other switch active when there is a failover of PA firewalls. The scenario you described is still functional regardless which HSRP switch is active at the time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the case of this scenario:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SW1( active for HSRP) ------&amp;gt;PA1 ( standby)&lt;BR /&gt;SW2( standby for HSRP)-----&amp;gt;PA2(Active)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic from PA2 will depending on your Layer 2 topology find its default gateway (HSRP Active switch) in SW1 by using interlink between SW2 and SW1.&lt;/P&gt;&lt;P&gt;Traffic from end host to PA, will have this flow: End user's traffic will land on SW1 (HSRP Active switch), static route's next hop IP will be resolved to MAC address of PA2 (Active Firewall), based on MAC address table, it will find outgoing interface interlink between SW1 and SW2, then traffic will arrive PA2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 13:36:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449650#M100958</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-11-26T13:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo alto HA and Cisco HSRP work together ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449655#M100959</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; , Thank you for your reply.&lt;/P&gt;&lt;P&gt;May I know what you have explained is same for both cisco catalyst and cisco nexus switches ?&lt;/P&gt;&lt;P&gt;Could also share if there is any document ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 14:00:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449655#M100959</guid>
      <dc:creator>perumalj</dc:creator>
      <dc:date>2021-11-26T14:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo alto HA and Cisco HSRP work together ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449664#M100961</link>
      <description>&lt;P&gt;I agree with your answer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will be looking forward to hearing your response for the following&amp;nbsp;&lt;/P&gt;&lt;P&gt;May I know what you have explained is same for both cisco catalyst and cisco nexus switches ?&lt;/P&gt;&lt;P&gt;Could also share if there is any document ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 15:05:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449664#M100961</guid>
      <dc:creator>perumalj</dc:creator>
      <dc:date>2021-11-26T15:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo alto HA and Cisco HSRP work together ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449723#M100971</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197203"&gt;@perumalj&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The behavior will be the same regardless you are going to use Catalyst or Nexus. The only difference will be if you enable vPC on Nexus side and configure port-channel on PA side, then HSRP will act as active active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have not found any document that exactly explains this and there is no best practice/design guide for PA &amp;lt;-&amp;gt; Nexus/Catalyst, however I have this deployment in several locations using&amp;nbsp;Nexus or Catalyst depending on site and failover on PA works fine without any changes to HSRP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 23:14:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-ha-and-cisco-hsrp-work-together/m-p/449723#M100971</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-11-26T23:14:29Z</dc:date>
    </item>
  </channel>
</rss>

