<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to use Seprate IPs on WAN interface of  2 Paloalto Firewall. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/491473#M104957</link>
    <description>&lt;P&gt;Is not possible to use any switches? In this way, you can connect the ISP to both FW (on the same port) without any problem. If you want to use another ISP for redundancy, use another port for both fw too.&lt;/P&gt;</description>
    <pubDate>Wed, 25 May 2022 09:51:27 GMT</pubDate>
    <dc:creator>LuisSantoTomas</dc:creator>
    <dc:date>2022-05-25T09:51:27Z</dc:date>
    <item>
      <title>How to use Seprate IPs on WAN interface of  2 Paloalto Firewall.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/489702#M104884</link>
      <description>&lt;P&gt;Im new in PaloAlto and configuring HA Active/Passive Mode with seprate IPs on WAN Interface in both Firewall, every thing is working fine but when Active Firewall 1 Syncronized with Firewall 2 its change the Firewall 2 WAN IP with Firewall 1 WAN IPs in that case my all routing to oustside is Block in Firewall 2 because it has different route outside than Firewall 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any one kinldy can guide me how i can design PaloAlto firewall WAN interfaces using Active/Passive Mode in case of Single ISP for both firewall or Dual ISP for better redundancy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aamirns_0-1653313000551.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41107i967A5423C70C891D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="aamirns_0-1653313000551.png" alt="aamirns_0-1653313000551.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 13:37:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/489702#M104884</guid>
      <dc:creator>aamirns</dc:creator>
      <dc:date>2022-05-23T13:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Seprate IPs on WAN interface of  2 Paloalto Firewall.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/489753#M104885</link>
      <description>&lt;P&gt;Why do A/P HA devices need different routes?&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 15:15:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/489753#M104885</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-05-23T15:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Seprate IPs on WAN interface of  2 Paloalto Firewall.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/489758#M104886</link>
      <description>&lt;P&gt;If we have two internet connection from same ISP or from Different ISP. for redundancy.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 15:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/489758#M104886</guid>
      <dc:creator>aamirns</dc:creator>
      <dc:date>2022-05-23T15:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Seprate IPs on WAN interface of  2 Paloalto Firewall.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/489763#M104887</link>
      <description>&lt;P&gt;You need the redundant circuit connected to both PAs, just like the primary.&amp;nbsp; Interface configuration and routes sync between active and passive nodes.&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha#id88817587-918d-4c99-8576-271b8df7ba6c" target="_blank" rel="noopener"&gt;Link - What doesn't sync between active/passive&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you'll need to choose how to utilize both circuits during normal operation and during failover.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 15:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/489763#M104887</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-05-23T15:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Seprate IPs on WAN interface of  2 Paloalto Firewall.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/489776#M104888</link>
      <description>&lt;P&gt;If you can see my visio i have only 2 internet connection one for each firewall either from Same ISP or Dual ISP.&amp;nbsp; every thing is working fine so far with Left side Firewall is in Active mode, but in case of failover when right side Firewall will become Acitve i want my traffic should go through its WAN IP. Problem is this HA syncrozised changed the WAN IP to same for both firewall. how i can overcome this situation WAN IP should be identical for both firewalls not same&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 15:46:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/489776#M104888</guid>
      <dc:creator>aamirns</dc:creator>
      <dc:date>2022-05-23T15:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Seprate IPs on WAN interface of  2 Paloalto Firewall.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/490013#M104900</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;in Active/Passive mode, the WAN IP's will be the same on the active firewall. Lets say Active firewall has IP 1.1.1.1, if there is a failover event the passive(no active) firewall will have its WAN IP of 1.1.1.1. There are only a few things that do not sync in HA, they are all on the Device tab.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are some links for reference:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIbCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIbCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 21:56:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/490013#M104900</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-05-23T21:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Seprate IPs on WAN interface of  2 Paloalto Firewall.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/491473#M104957</link>
      <description>&lt;P&gt;Is not possible to use any switches? In this way, you can connect the ISP to both FW (on the same port) without any problem. If you want to use another ISP for redundancy, use another port for both fw too.&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 09:51:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/491473#M104957</guid>
      <dc:creator>LuisSantoTomas</dc:creator>
      <dc:date>2022-05-25T09:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Seprate IPs on WAN interface of  2 Paloalto Firewall.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/495733#M105091</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You sure can, just need to make sure that the configuration and routing is correct. However with regards to HA, in active/passive mode, only 1 firewall is Active so the other one has its ports shut down.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 15:15:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/495733#M105091</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-05-31T15:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Seprate IPs on WAN interface of  2 Paloalto Firewall.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/585982#M116951</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you configure your ISP connections on separate firewall ports you should achieve what you want.&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;P&gt;ISP1 configured on Ethernet1/7 and ISP2 configured on Ethernet1/8.&lt;/P&gt;
&lt;P&gt;On the active firewall connect only ISP1 on Ethernet1/7 and on passive firewall connect only ISP2 on Ethernet1/8.&lt;/P&gt;
&lt;P&gt;On both firewall you will have 2 default routes pointing to every ISP next hop and the active firewall will chose one of them based on connectivity status.&lt;/P&gt;
&lt;P&gt;Also, you need to take care of some source NAT, if it's the case.&lt;/P&gt;
&lt;P&gt;Basically, you will make the configuration like both ISP are connected to the same firewall. on different interfaces.&lt;/P&gt;
&lt;P&gt;What will be different, and you will configure on each firewall are automatic failover conditions.&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 09:13:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-seprate-ips-on-wan-interface-of-2-paloalto-firewall/m-p/585982#M116951</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2024-05-07T09:13:22Z</dc:date>
    </item>
  </channel>
</rss>

