<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High availability Links on different locations in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/high-availability-links-on-different-locations/m-p/588717#M117366</link>
    <description>&lt;P&gt;If this is not ridiculously expensive, i would recommend you get a secondary ha1(backup) link.&lt;/P&gt;
&lt;P&gt;If both ha1 links go through the same fiber, a fiber cut will cause a split brain: both firewalls will become active and claim the IP addresses (dynamic routing and gratuitous arp) which may cause even more trouble to deal with&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you have a physical ha1 backup link, a link failure would be less catastrophic&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jun 2024 11:27:17 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2024-06-04T11:27:17Z</dc:date>
    <item>
      <title>High availability Links on different locations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/high-availability-links-on-different-locations/m-p/588689#M117360</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;we have 2 PA1410 on two different buildings. They act in an active-passive cluster.&lt;/P&gt;
&lt;P&gt;On each location is a switch, and the Firewall ist connected with all of its port (ha1a, ha1b, ha2, MGM, Data) to the switch.&lt;/P&gt;
&lt;P&gt;The switches are connected though a glasfiber to each other.&lt;/P&gt;
&lt;P&gt;Does it make sense, to buy a fiber sfp transceiver for each firewall and connect a ha1-link directly to the other firewall?&lt;/P&gt;
&lt;P&gt;Then&amp;nbsp; the HA1 Link is connected through the HA1A Port to the switch and Backup HA1 Link is connected through a sfp Transceiver directly to the other system.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 07:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/high-availability-links-on-different-locations/m-p/588689#M117360</guid>
      <dc:creator>IT-Esp</dc:creator>
      <dc:date>2024-06-04T07:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: High availability Links on different locations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/high-availability-links-on-different-locations/m-p/588717#M117366</link>
      <description>&lt;P&gt;If this is not ridiculously expensive, i would recommend you get a secondary ha1(backup) link.&lt;/P&gt;
&lt;P&gt;If both ha1 links go through the same fiber, a fiber cut will cause a split brain: both firewalls will become active and claim the IP addresses (dynamic routing and gratuitous arp) which may cause even more trouble to deal with&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you have a physical ha1 backup link, a link failure would be less catastrophic&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 11:27:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/high-availability-links-on-different-locations/m-p/588717#M117366</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-06-04T11:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: High availability Links on different locations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/high-availability-links-on-different-locations/m-p/588730#M117369</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1109826275"&gt;@IT-Esp&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;we have 2 PA1410 on two different buildings. They act in an active-passive cluster.&lt;/P&gt;
&lt;P&gt;On each location is a switch, and the Firewall ist connected with all of its port (ha1a, ha1b, ha2, MGM, Data) to the switch.&lt;/P&gt;
&lt;P&gt;The switches are connected though a glasfiber to each other.&lt;/P&gt;
&lt;P&gt;Does it make sense, to buy a fiber sfp transceiver for each firewall and connect a ha1-link directly to the other firewall?&lt;/P&gt;
&lt;P&gt;Then&amp;nbsp; the HA1 Link is connected through the HA1A Port to the switch and Backup HA1 Link is connected through a sfp Transceiver directly to the other system.&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I would say it would depend on how the 2 buildings are already connected to each other and how much do you trust that connectivity?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There was a time that my company's DC was split between 2 geographic location 180+ miles apart and we had a HA A/P FW split across that distance.&amp;nbsp; We used dedicated P2P fiber and we had no issues.&amp;nbsp; Only ever used HA1/HA2 and never used a backup link for HA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We did use the management port as a heartbeat backup as a fail-safe.&amp;nbsp; Using this design as long as those P2P links between the DCs never went down we never had an issue with split HA across this distance.&amp;nbsp; In this design you can use copper or fiber locally as desired for your HA.&amp;nbsp; I don't really see a reason to pay for yet another fiber link from an ISP to support a HA-backup connection.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Brandon_Wertz_0-1717508610841.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60170i802559C8864A119F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Brandon_Wertz_0-1717508610841.png" alt="Brandon_Wertz_0-1717508610841.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 13:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/high-availability-links-on-different-locations/m-p/588730#M117369</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-06-04T13:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: High availability Links on different locations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/high-availability-links-on-different-locations/m-p/588761#M117372</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1109826275"&gt;@IT-Esp&lt;/a&gt;&amp;nbsp; We have few PA across the DC running in Active Passive Mode.&lt;/P&gt;
&lt;P&gt;We have Two Switches in Each DC running VRRP.&lt;/P&gt;
&lt;P&gt;HA1 and HA1B has connection to local switch in each DC.&lt;/P&gt;
&lt;P&gt;HA2 we have Single Mode connection directly between the firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA2 backup also has connection to Local switch.&lt;/P&gt;
&lt;P&gt;We have no issues with this design.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 19:40:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/high-availability-links-on-different-locations/m-p/588761#M117372</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2024-06-04T19:40:11Z</dc:date>
    </item>
  </channel>
</rss>

