<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active-Active Firewall - BGP failure condition in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-firewall-bgp-failure-condition/m-p/518534#M107571</link>
    <description>&lt;P&gt;Is the expectation that BGP to the provider goes down on A-P that traffic will then go to A-S? I assume you've preferenced the prefix(es) learned through A-P so that's the better path from your internal gear.&lt;/P&gt;
&lt;P&gt;When BGP on A-P goes down, those prefixes should be withdrawn and traffic goes to A-S. Sounds like that's happening.&lt;/P&gt;
&lt;P&gt;What does the routing table look like on A-S when BGP is down on A-P?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does a traceroute show?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Oct 2022 16:07:03 GMT</pubDate>
    <dc:creator>rmfalconer</dc:creator>
    <dc:date>2022-10-20T16:07:03Z</dc:date>
    <item>
      <title>Active-Active Firewall - BGP failure condition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-firewall-bgp-failure-condition/m-p/518111#M107492</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I instigate a firewall failover for an Active-Active firewall if BGP fails? I feel I need a full failover but please tell me if I am wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the situation: Firewall in Active-Active mode, HA1,2 and 3 up. BGP peering on outside and inside interface. 1 BGP peer on outside to local cpe. Inside peers to local cpe and remote datacentre cpe for resilience. When the BGP fails on the outside path, the inside peering is still up - traffic fails over to the Active-Secondary I thought the the traffic would route through the HA3 link but the traffic path just fails - failed ping that is - I think it's going through Active-Secondary with route back through Active-Primary with no outside network established - does that make sense?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How could we mitigate against this failure? Having dual peering on the outside is not an option. If the interface fails it is configured to failover but this scenario is that the bgp drops and the interface stays up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 15:23:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-firewall-bgp-failure-condition/m-p/518111#M107492</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2022-10-17T15:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active-Active Firewall - BGP failure condition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-firewall-bgp-failure-condition/m-p/518534#M107571</link>
      <description>&lt;P&gt;Is the expectation that BGP to the provider goes down on A-P that traffic will then go to A-S? I assume you've preferenced the prefix(es) learned through A-P so that's the better path from your internal gear.&lt;/P&gt;
&lt;P&gt;When BGP on A-P goes down, those prefixes should be withdrawn and traffic goes to A-S. Sounds like that's happening.&lt;/P&gt;
&lt;P&gt;What does the routing table look like on A-S when BGP is down on A-P?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does a traceroute show?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 16:07:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-firewall-bgp-failure-condition/m-p/518534#M107571</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-10-20T16:07:03Z</dc:date>
    </item>
  </channel>
</rss>

