<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Active VIP ping inconsistent in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-vip-ping-inconsistent/m-p/518551#M107576</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;i have 2 Firewalls configured in HA Active Active.&lt;/P&gt;
&lt;P&gt;I have a L3 sub interface created on each firewall and a vitual address configured as IP-Modulo arp-load-sharing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ex:&lt;/P&gt;
&lt;P&gt;FW1 (primary): 192.168.0.2/24&lt;/P&gt;
&lt;P&gt;FW2 (secondary): 192.168.0.3/24&lt;/P&gt;
&lt;P&gt;Virtual IP (ip modulo): 192.168.0.1/24&lt;/P&gt;
&lt;P&gt;zone: trust&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a management profile is configured on both FW1 and FW2 to allow ping on the interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;clients on the LAN (192.168.0.10/24) can ping all 3 IP addresses.&lt;/P&gt;
&lt;P&gt;clients on another zone of the firewall can ping FW2 192.168.0.3 (secondary) and are unable to ping FW1 (primary) 192.168.0.2 or the VIP 192.168.0.1.&lt;/P&gt;
&lt;P&gt;clients on another zone can also ping devices on the LAN without issues. ex: ping 192.168.0.10/24&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my question, why can't i ping the VIP 192.168.0.1 from the DMZ zone. shouldn't the VIP be accessible on both Active and Secondary firewalls.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Oct 2022 18:55:09 GMT</pubDate>
    <dc:creator>Ricky_Levesque</dc:creator>
    <dc:date>2022-10-20T18:55:09Z</dc:date>
    <item>
      <title>Active Active VIP ping inconsistent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-vip-ping-inconsistent/m-p/518551#M107576</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;i have 2 Firewalls configured in HA Active Active.&lt;/P&gt;
&lt;P&gt;I have a L3 sub interface created on each firewall and a vitual address configured as IP-Modulo arp-load-sharing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ex:&lt;/P&gt;
&lt;P&gt;FW1 (primary): 192.168.0.2/24&lt;/P&gt;
&lt;P&gt;FW2 (secondary): 192.168.0.3/24&lt;/P&gt;
&lt;P&gt;Virtual IP (ip modulo): 192.168.0.1/24&lt;/P&gt;
&lt;P&gt;zone: trust&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a management profile is configured on both FW1 and FW2 to allow ping on the interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;clients on the LAN (192.168.0.10/24) can ping all 3 IP addresses.&lt;/P&gt;
&lt;P&gt;clients on another zone of the firewall can ping FW2 192.168.0.3 (secondary) and are unable to ping FW1 (primary) 192.168.0.2 or the VIP 192.168.0.1.&lt;/P&gt;
&lt;P&gt;clients on another zone can also ping devices on the LAN without issues. ex: ping 192.168.0.10/24&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my question, why can't i ping the VIP 192.168.0.1 from the DMZ zone. shouldn't the VIP be accessible on both Active and Secondary firewalls.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 18:55:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-vip-ping-inconsistent/m-p/518551#M107576</guid>
      <dc:creator>Ricky_Levesque</dc:creator>
      <dc:date>2022-10-20T18:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Active Active VIP ping inconsistent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-vip-ping-inconsistent/m-p/520798#M107956</link>
      <description>&lt;P&gt;ARP can be a tricky creature if your network devices don't want to play along&lt;/P&gt;
&lt;P&gt;your switch (or router) may be 'locking' the virtual IP/MAC of the firewall on one port, or the IP to one MAC, causing this behavior&lt;/P&gt;
&lt;P&gt;are you able to verify this? (you should be able to packetcapture ARP at the router to see if you're getting onl;y one reply, and looking at the MAC table for the switch to see if it's associating the IP to just one port or something)&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 14:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-vip-ping-inconsistent/m-p/520798#M107956</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2022-11-09T14:29:23Z</dc:date>
    </item>
  </channel>
</rss>

