<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How and when to use ARP-Loadsharing and Floating IP - Upstream/Uplinks in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-and-when-to-use-arp-loadsharing-and-floating-ip-upstream/m-p/546298#M111662</link>
    <description>&lt;P&gt;How and when to use ARP-Loadsharing and Floating IP - Upstream/Uplinks&lt;/P&gt;
&lt;P&gt;Hello Live comunity, how are you all doing.&lt;/P&gt;
&lt;P&gt;In the use cases you can see that the use of ARP Load-sharing or IP Floating, ARP is used thinking in the access to the Gateway vs IP Floating that is something more like fail-over more like an active/passive so to speak, than ARP Load-sharing that distributes vs Ip floating that acts as fail over.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Why wouldn't you use ARP Loadsharing or when would you use it thinking purely in Upstream/Uplinks?&lt;/P&gt;
&lt;P&gt;-I was thinking in cases where the external/IP or Uplinks/Upstream interface of the HA Firewall, is a route of some router or superior device, that points to the HA IP, ARP-Load sharing, could in this case point to an ARP Loadsharing IP as well or not ?&lt;/P&gt;
&lt;P&gt;-Now thinking about if it is a totally edge firewall, perimeter, where it has DNAT, and so on, maybe there we have limitations of using ARP loadsharing vs IP Flaoting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If someone has already worked too much with HA Active/Active firewall or has mastered very well the theory and concepts regarding the use in Uplinks/Upstream, where to use ARP-Loadsharing / IP Floating. Or anyone who wants to add their comments.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for your time, your collaboration and your comments.&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
    <pubDate>Sat, 17 Jun 2023 04:27:24 GMT</pubDate>
    <dc:creator>Metgatz</dc:creator>
    <dc:date>2023-06-17T04:27:24Z</dc:date>
    <item>
      <title>How and when to use ARP-Loadsharing and Floating IP - Upstream/Uplinks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-and-when-to-use-arp-loadsharing-and-floating-ip-upstream/m-p/546298#M111662</link>
      <description>&lt;P&gt;How and when to use ARP-Loadsharing and Floating IP - Upstream/Uplinks&lt;/P&gt;
&lt;P&gt;Hello Live comunity, how are you all doing.&lt;/P&gt;
&lt;P&gt;In the use cases you can see that the use of ARP Load-sharing or IP Floating, ARP is used thinking in the access to the Gateway vs IP Floating that is something more like fail-over more like an active/passive so to speak, than ARP Load-sharing that distributes vs Ip floating that acts as fail over.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Why wouldn't you use ARP Loadsharing or when would you use it thinking purely in Upstream/Uplinks?&lt;/P&gt;
&lt;P&gt;-I was thinking in cases where the external/IP or Uplinks/Upstream interface of the HA Firewall, is a route of some router or superior device, that points to the HA IP, ARP-Load sharing, could in this case point to an ARP Loadsharing IP as well or not ?&lt;/P&gt;
&lt;P&gt;-Now thinking about if it is a totally edge firewall, perimeter, where it has DNAT, and so on, maybe there we have limitations of using ARP loadsharing vs IP Flaoting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If someone has already worked too much with HA Active/Active firewall or has mastered very well the theory and concepts regarding the use in Uplinks/Upstream, where to use ARP-Loadsharing / IP Floating. Or anyone who wants to add their comments.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for your time, your collaboration and your comments.&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2023 04:27:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-and-when-to-use-arp-loadsharing-and-floating-ip-upstream/m-p/546298#M111662</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-06-17T04:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: How and when to use ARP-Loadsharing and Floating IP - Upstream/Uplinks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-and-when-to-use-arp-loadsharing-and-floating-ip-upstream/m-p/547717#M111872</link>
      <description>&lt;P&gt;- arp loadsharing is 'sticky' in a sense that it uses an algorithm to determine which 'source' is handled by each firewall. if you have an internal (NAT)router or proxy for example, that could easily skew how the 'sharing' part actually works.&lt;/P&gt;
&lt;P&gt;for load sharing i'd sooner rely on ECMP if that's an option instead of distributing among chassis&lt;/P&gt;
&lt;P&gt;- i guess that could also work&lt;/P&gt;
&lt;P&gt;- if your perimeter is L2 connected so both firewalls can use the same public IP, load sharing could work, but what do you see as the added value of doing this? stretching the firewall's capacity (1+1=2) is dangerous in case of failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I usually resort to floating IP so i can easily predict which firewall is used for what and only when there is a failover the traffic will shift.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 13:03:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-and-when-to-use-arp-loadsharing-and-floating-ip-upstream/m-p/547717#M111872</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-06-29T13:03:26Z</dc:date>
    </item>
  </channel>
</rss>

