<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HA mode with vwire in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-mode-with-vwire/m-p/563390#M114094</link>
    <description>&lt;P&gt;Not sure it this is the right location for this question but here we go ...&lt;BR /&gt;I'm trying to replace 2 transparent ASA's in ACT/STDBY with 2 Palo's in the same setup vwire ACT/PAS. Current setup is the asa's are connected to 2 vpn servers in ACT/PAS config, the asa’s have a 3 interface BVI (2 inside interfaces one to each vpn server and 1 outside interface to upstream switch). The vpn servers built ipsec vpn tunnels THROUGH the asa’s to the other endpoint everything works fine. What I did but didn’t work fully was build 2 PAs in HA, for the 2 inside interfaces I put them into an AE grp and then put both the outside and AE interfaces into the same vwire instance this setup did not work as expected. Any assistance would be great .. tks&lt;/P&gt;</description>
    <pubDate>Fri, 27 Oct 2023 14:56:48 GMT</pubDate>
    <dc:creator>Wayne_Fealy</dc:creator>
    <dc:date>2023-10-27T14:56:48Z</dc:date>
    <item>
      <title>HA mode with vwire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-mode-with-vwire/m-p/563390#M114094</link>
      <description>&lt;P&gt;Not sure it this is the right location for this question but here we go ...&lt;BR /&gt;I'm trying to replace 2 transparent ASA's in ACT/STDBY with 2 Palo's in the same setup vwire ACT/PAS. Current setup is the asa's are connected to 2 vpn servers in ACT/PAS config, the asa’s have a 3 interface BVI (2 inside interfaces one to each vpn server and 1 outside interface to upstream switch). The vpn servers built ipsec vpn tunnels THROUGH the asa’s to the other endpoint everything works fine. What I did but didn’t work fully was build 2 PAs in HA, for the 2 inside interfaces I put them into an AE grp and then put both the outside and AE interfaces into the same vwire instance this setup did not work as expected. Any assistance would be great .. tks&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 14:56:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-mode-with-vwire/m-p/563390#M114094</guid>
      <dc:creator>Wayne_Fealy</dc:creator>
      <dc:date>2023-10-27T14:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: HA mode with vwire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-mode-with-vwire/m-p/563430#M114096</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155682"&gt;@Wayne_Fealy&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From reading your post, it sounds like you have 3 interfaces in transparent mode.&amp;nbsp; A VWire is for mapping interfaces1-to-1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You want to create 3 x L2 interfaces, and put them into the same VLAN.&amp;nbsp; Put the interfaces in L2 zones, inside and outside (or you could do 3 zones to limit intrazone traffic between the 2 VPN servers).&amp;nbsp; Then your security policy rules will follow naturally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank will work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2023 01:28:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-mode-with-vwire/m-p/563430#M114096</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-10-28T01:28:01Z</dc:date>
    </item>
  </channel>
</rss>

