<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HA Cluster Topologies and experiences in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/462815#M102304</link>
    <description>&lt;P&gt;Has anyone had some hands on experiences with the new clustering features?&amp;nbsp; &amp;nbsp;I've read a bit on them, but like the post below, am struggling to make sense of the actual functionality/workability of the finer details needed for this setup as to how it exactly functions for multi data center scalability.&amp;nbsp; Curious as to how the addressing scheme works in situations where you have multiple active data centers.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-network-topology/m-p/365084#M88535" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-network-topology/m-p/365084#M88535&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Feb 2022 14:42:40 GMT</pubDate>
    <dc:creator>Sec101</dc:creator>
    <dc:date>2022-02-02T14:42:40Z</dc:date>
    <item>
      <title>HA Cluster Topologies and experiences</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/462815#M102304</link>
      <description>&lt;P&gt;Has anyone had some hands on experiences with the new clustering features?&amp;nbsp; &amp;nbsp;I've read a bit on them, but like the post below, am struggling to make sense of the actual functionality/workability of the finer details needed for this setup as to how it exactly functions for multi data center scalability.&amp;nbsp; Curious as to how the addressing scheme works in situations where you have multiple active data centers.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-network-topology/m-p/365084#M88535" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-network-topology/m-p/365084#M88535&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 14:42:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/462815#M102304</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2022-02-02T14:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster Topologies and experiences</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/463558#M102383</link>
      <description>&lt;P&gt;Depends on the use case. If the goal is service survivability (failover), then clustering is great! Because the session data lives between all the HA pairs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the goal is more horizontal scaling (aka utilizing both DCs in real time) that is obviously best accomplished frontended or sandwiched by load balancers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not an expert by any means, but have 1 customer running this in prod and know the PM for the feature. What questions can I check on for you?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 22:18:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/463558#M102383</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2022-02-04T22:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster Topologies and experiences</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/479864#M103951</link>
      <description>&lt;P&gt;Hi Slick,&lt;/P&gt;&lt;P&gt;We have been trying to configure HA Cluster in our lab environment. We have already tried on two architecture:&lt;/P&gt;&lt;P&gt;i) Three sites as an Active.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SudipRijal_0-1649747438391.png" style="width: 133px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40122i5C96AEF8C1F2C2B1/image-dimensions/133x49/is-moderation-mode/true?v=v2" width="133" height="49" role="button" title="SudipRijal_0-1649747438391.png" alt="SudipRijal_0-1649747438391.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;ii) Active/Passive as in DC and Standalone (Active) as in DR&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SudipRijal_1-1649747526117.png" style="width: 129px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40123i4AC9046609ADAEC6/image-dimensions/129x104/is-moderation-mode/true?v=v2" width="129" height="104" role="button" title="SudipRijal_1-1649747526117.png" alt="SudipRijal_1-1649747526117.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We raised multiple tickets in support portals but none of the representative were able to support effectively on this. What actually HA Cluster does? If the primary firewall goes down, it is responsible for session synchronization to the cluster members and traffic should to transferred to another member on the cluster, right? Since, configuration on all of the devices are same. We got ARP conflict on each of the firewall in the cluster. But, we assumed that it would be managed by the clustering itself right? We got some ip conflict related issues.&lt;/P&gt;&lt;P&gt;The KB we referred is:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/high-availability/ha-clustering-overview" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/high-availability/ha-clustering-overview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 08:41:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/479864#M103951</guid>
      <dc:creator>SudipRijal</dc:creator>
      <dc:date>2022-04-12T08:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster Topologies and experiences</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/479912#M103958</link>
      <description>&lt;P&gt;I believe there is a single support team for this feature, which is why we highly recommend this feature be implemented through professional services. Yes, if a firewall pair goes down then the cluster should pick a new cluster member to move traffic to.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ARP and IP addresses become the same through the failover. That's how a seamless failover event is created. For example, I have an A/P firewall pair right now, if the primary fails, the same MAC/IP addresses are taken by the passive. Same concept in HA4&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 15:20:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/479912#M103958</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2022-04-12T15:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster Topologies and experiences</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/480397#M104018</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160615"&gt;@LAYER_8&lt;/a&gt;&amp;nbsp; I thought that the mac/ip addresses were completely different in a cluster setup - it was specifically just for state?&amp;nbsp; MAC/IP only stay the same in an HA pair, not throughout the cluster?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 15:29:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/480397#M104018</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2022-04-14T15:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster Topologies and experiences</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/480440#M104028</link>
      <description>&lt;P&gt;Ah yes, worthwhile correction. Apologies&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 18:58:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-topologies-and-experiences/m-p/480440#M104028</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2022-04-14T18:58:57Z</dc:date>
    </item>
  </channel>
</rss>

