<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HSBI and HA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/572855#M115246</link>
    <description>&lt;P&gt;Thanks for answering, I appreciate you, you made my day.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 10:55:12 GMT</pubDate>
    <dc:creator>ModestaZieme</dc:creator>
    <dc:date>2024-01-12T10:55:12Z</dc:date>
    <item>
      <title>HSBI and HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/568468#M114731</link>
      <description>&lt;P&gt;Folks,&lt;/P&gt;
&lt;P&gt;I would like understand the difference between HSBI and HA1, HA1B, HA2, HA2B&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per my understanding&lt;/P&gt;
&lt;P&gt;HA1 for control &amp;amp; HA1B for backup link&lt;/P&gt;
&lt;P&gt;HA2 for data &amp;amp; HA2B for backup link&amp;nbsp;&lt;/P&gt;
&lt;P&gt;control carries &amp;nbsp;heartbeats and communication&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dara traffic carries Ip table, arp table, session table? Is that correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For state full session sync up we “must” use HSBI link? Or it can be used for over HA2?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have little expertise in PA, but I never see such implementation?&lt;/P&gt;
&lt;P&gt;can you please clarify?&lt;/P&gt;
&lt;P&gt;your swift response is much appreciated&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 17:01:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/568468#M114731</guid>
      <dc:creator>Ramakrishnan</dc:creator>
      <dc:date>2023-12-05T17:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: HSBI and HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/568691#M114753</link>
      <description>&lt;P&gt;HA1 is the 'brains' of the HA cluster, sharing configuration, routing information, control messages to see if the peer is alive and functional, etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA1b is a backup link (if for some reason HA1 is disconected but both firewalls are still fully functional, they will assume the remote peer is down and both start accepting packets at the same time, this is not fun to have happen, so make sure to set up HA1b)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA2 is where the session table gets synced so if a firewall goes down the perr can pick up existing sessions&lt;/P&gt;
&lt;P&gt;ha2b is the backup link&lt;/P&gt;
&lt;P&gt;you are not required to use the HSCI link, you can assign the type 'HA' to dataplane interfaces and use those instead&lt;/P&gt;
&lt;P&gt;you cannot use HSCI for HA1 connections, but you should either use the dedidicated HA1a/HA1b, the AUX1/AUX2, or dataplane interfaces (dedicated links preferred)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 14:41:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/568691#M114753</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-12-06T14:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: HSBI and HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/568808#M114760</link>
      <description>&lt;P&gt;I have one last doubt/clarity.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If we run HA1 and HA2 between firewalls as below back-to-back links.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[FW1 HA1 &amp;lt; --- &amp;gt; FW2 HA1] - No backup link considered&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[FW1 HA2 &amp;lt; -- &amp;gt;&amp;nbsp; FW2 HA2] -&amp;nbsp;No backup link considered&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So No need of HSCI, since all session sync up will happen over HA2 ? So during Active device fails passive will become active and pick up the session, from an end-user perspective no need for session reinitiation? Is my understanding correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 04:17:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/568808#M114760</guid>
      <dc:creator>Ramakrishnan</dc:creator>
      <dc:date>2023-12-07T04:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: HSBI and HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/568990#M114792</link>
      <description>&lt;P&gt;I have two 1410 firewall. I have connected two cables on HA1a, HA1b and HSCI. Now should I use HSCI port for HA2 communication?&amp;nbsp; In fact, its forcibly selected HSCI for HA2 communication, please help me understand.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My second question is its not mandate to configure IP for HA2 correct? And HA1 we need give same IP under the general settings?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 05:12:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/568990#M114792</guid>
      <dc:creator>Ramakrishnan</dc:creator>
      <dc:date>2023-12-08T05:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: HSBI and HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/569054#M114806</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/178856"&gt;@Ramakrishnan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Please check the following documentations -&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/hardware/pa-1400-hardware-reference/pa-1400-series-overview/front-panel-1400-series" target="_blank"&gt;https://docs.paloaltonetworks.com/hardware/pa-1400-hardware-reference/pa-1400-series-overview/front-panel-1400-series&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/ha-concepts/ha-links-and-backup-links/ha-ports-on-the-pa-7000-series-firewall" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/ha-concepts/ha-links-and-backup-links/ha-ports-on-the-pa-7000-series-firewall&lt;/A&gt;&lt;BR /&gt;HSCI is high speed interface, which main purpose is to be used for HA2. As &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; already mentined HA2 is data link, it is used to sync session information between the two HA members. (and also forward traffic in case you use active/active). &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;So if you have the physical capability to connect both member directly (no routers, no switches, no other intermediate devices), it is always recommend to&amp;nbsp; use the HSCI for HA2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you cannot connect both peer directly, you can reserve one of the data plane interfaces for HA and then configure HA2 to use that dataplane interface. By default no dataplane interface is being reserved for HA, that is why when you try to edit HA your dropdown offers only HSCI.&lt;BR /&gt;&lt;BR /&gt;Regarding the IP addresses:&lt;/P&gt;
&lt;P&gt;- As you can see from above links HSCI is layer1 interface, so must use "ethernet" for HA2 transport, which used PAN custom/properiotry ethernet frames which doesn't use IP address. So even if you set some addresses they will be ignored if transport is set to ethernet&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Transport
—Choose one of the following transport options:

    Ethernet
    —Use when the firewalls are connected back-to-back or through a switch (Ethertype 0x7261).
    IP
    —Use when Layer 3 transport is required (IP protocol number 99).
    UDP
    —Use to take advantage of the fact that the checksum is calculated on the entire packet rather than just the header, as in the IP option (UDP port 29281). The benefit of using UDP mode is the presence of the UDP checksum to verify the integrity of a session sync message.&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For HA1 you must use IP addresses and you must have different addresses for each member. If you connect them directly you have to specify the same subnet. If they are not connected directly you should configure a gateway which will route between the two networks.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 13:00:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/569054#M114806</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-12-08T13:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: HSBI and HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/572855#M115246</link>
      <description>&lt;P&gt;Thanks for answering, I appreciate you, you made my day.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 10:55:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hsbi-and-ha/m-p/572855#M115246</guid>
      <dc:creator>ModestaZieme</dc:creator>
      <dc:date>2024-01-12T10:55:12Z</dc:date>
    </item>
  </channel>
</rss>

