<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HA Active/Active design in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-design/m-p/1453#M1117</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would like to deploy 2 PAs on two different sites in an Active/active design. The two sites are 10ms far away from each other.&lt;/P&gt;&lt;P&gt;So the first question is : &lt;STRONG&gt;Is 10ms (RTT) acceptable from a PanOS perspective to enable the HA feature&lt;/STRONG&gt; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IP plan is not the same on each site. Is it an issue to setup HA active/active in this case ?&amp;nbsp; I've read the documentation, and it seems to be supported if we use the virtual wire implementation case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best wishes for this new year.&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EDIT : I've just found a Tech Note describing the HA/HA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the second question, this documentation gives the answer : we can use the Route Based Redundancy, that's fine.&lt;/P&gt;&lt;P&gt;But now, I worry about the load sharing feature. In our case, half of our users are located on site 1 and second half on site 2, So the&lt;/P&gt;&lt;P&gt;load sharind is native by design using some IP routing features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding, the session owner, it's easy, we can define it as being the device receiving the first packet.&lt;/P&gt;&lt;P&gt;But regarding the session setup, it's not clear : &lt;STRONG&gt;how to ensure that the session setup is the device closest to the user ?&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Jan 2012 15:35:47 GMT</pubDate>
    <dc:creator>bdaussin</dc:creator>
    <dc:date>2012-01-03T15:35:47Z</dc:date>
    <item>
      <title>HA Active/Active design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-design/m-p/1453#M1117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would like to deploy 2 PAs on two different sites in an Active/active design. The two sites are 10ms far away from each other.&lt;/P&gt;&lt;P&gt;So the first question is : &lt;STRONG&gt;Is 10ms (RTT) acceptable from a PanOS perspective to enable the HA feature&lt;/STRONG&gt; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IP plan is not the same on each site. Is it an issue to setup HA active/active in this case ?&amp;nbsp; I've read the documentation, and it seems to be supported if we use the virtual wire implementation case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best wishes for this new year.&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EDIT : I've just found a Tech Note describing the HA/HA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the second question, this documentation gives the answer : we can use the Route Based Redundancy, that's fine.&lt;/P&gt;&lt;P&gt;But now, I worry about the load sharing feature. In our case, half of our users are located on site 1 and second half on site 2, So the&lt;/P&gt;&lt;P&gt;load sharind is native by design using some IP routing features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding, the session owner, it's easy, we can define it as being the device receiving the first packet.&lt;/P&gt;&lt;P&gt;But regarding the session setup, it's not clear : &lt;STRONG&gt;how to ensure that the session setup is the device closest to the user ?&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 15:35:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-design/m-p/1453#M1117</guid>
      <dc:creator>bdaussin</dc:creator>
      <dc:date>2012-01-03T15:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Active design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-design/m-p/1454#M1118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We developed A/A HA in order to address high availability in environments with asymmetric routing. In these cases, we expect race conditions with packets arriving at both devices. The session setup operation must be tied to a specific device (chosen by the IP modulo or the hash of certain IP header fields) in order to avoid the scenario where both devices try to create a session. For these reasons, we don't currently support a configuration where the device closest to the users will setup the session. Fortunately, the session setup operation is relatively light. Assuming you select the "first-packet" option for session ownership, your A/A design will be as efficient as possible in a symmetrically routed environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Nick Campagna&lt;/P&gt;&lt;P&gt;Product Management&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 18:28:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-design/m-p/1454#M1118</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2012-01-03T18:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Active design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-design/m-p/1455#M1119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you for your answer Nick &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;With a symmetrical routing design, If I anderstand well, only the session setup ( first few packets ) will be sent through the HA3 link, so&lt;/P&gt;&lt;P&gt;it should not be so dramatic. Once the session has been established, the PA which owns the session, will be able to analyse and forward&lt;/P&gt;&lt;P&gt;the packet without always sending packets to HA3 link. Am I right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my original question, what about the 10ms RTT between our 2 PAs ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;P&gt;- Benjamin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 03:43:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-design/m-p/1455#M1119</guid>
      <dc:creator>bdaussin</dc:creator>
      <dc:date>2012-01-04T03:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Active design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-design/m-p/1456#M1120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Benjamin, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Thanks you for your answer Nick &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;With a symmetrical routing design, If I anderstand well, only the session setup ( first few packets ) will be sent through the HA3 link, so&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;it should not be so dramatic. Once the session has been established, the PA which owns the session, will be able to analyse and forward&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;the packet without always sending packets to HA3 link. Am I right ?&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;&lt;STRONG&gt;[NC] You've got it!&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;In my original question, what about the 10ms RTT between our 2 PAs ?&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;&lt;STRONG&gt;[NC] You'll have to look at your specific applications and their tolerance for latency.&amp;nbsp; Since this 10ms RTT will typically only affect the session for the first few packets, I don't anticipate any issues.&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Thanks for your help &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;- Benjamin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 16:19:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-design/m-p/1456#M1120</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2012-01-04T16:19:00Z</dc:date>
    </item>
  </channel>
</rss>

