<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA Active/Passive  and Cisco stacking LACP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/594723#M118374</link>
    <description>&lt;P&gt;Great,&lt;/P&gt;
&lt;P&gt;For LACP should be active or Passive ?on cisco and PA,,,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
    <pubDate>Tue, 13 Aug 2024 12:32:07 GMT</pubDate>
    <dc:creator>K.Mohamed</dc:creator>
    <dc:date>2024-08-13T12:32:07Z</dc:date>
    <item>
      <title>PA Active/Passive  and Cisco stacking LACP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/594593#M118340</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have setup Active/ Passive connected with cisco stacking 9500 with four links full-mesh as shown below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Paloalto active:&lt;/P&gt;
&lt;P&gt;PA(active)&amp;nbsp; AE1 ========= cisco-1 switch (Etherchanel 10)&lt;/P&gt;
&lt;P&gt;PA(active)&amp;nbsp; AE1 ========= cisco-2 switch&amp;nbsp;(Etherchanel 20)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Paloalto Passive:&lt;/P&gt;
&lt;P&gt;PA(passive)&amp;nbsp; AE1 ========= cisco-1 switch (Etherchanel 10)&lt;/P&gt;
&lt;P&gt;PA(passive)&amp;nbsp; AE1 ========= cisco-2 switch&amp;nbsp;(Etherchanel 20)&lt;/P&gt;
&lt;P&gt;=================================================&lt;/P&gt;
&lt;P&gt;Is the connection and configuration is correct or i should create 2 channels from Paloalto side like this example?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 08:21:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/594593#M118340</guid>
      <dc:creator>K.Mohamed</dc:creator>
      <dc:date>2024-08-12T08:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: PA Active/Passive  and Cisco stacking LACP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/594678#M118367</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/423508891"&gt;@K.Mohamed&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to me this configuration does not look ideal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are having 2 ports on PA side in a single port channel group and on Cisco side each port is in different port channel group. With this configuration you might have an issue with Cisco's EtherChannel guard kicking in to take ports into error disabled state.&lt;/P&gt;
&lt;P&gt;Personally I would configure port channel 10 to Active Firewall and port channel 20 to Passive Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Paloalto active:&lt;/P&gt;
&lt;P&gt;PA(active) AE1 ========= cisco-1 switch (Etherchanel 10)&lt;/P&gt;
&lt;P&gt;PA(active) AE1 ========= cisco-2 switch (Etherchanel 10)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Paloalto Passive:&lt;/P&gt;
&lt;P&gt;PA(passive) AE1 ========= cisco-1 switch (Etherchanel 20)&lt;/P&gt;
&lt;P&gt;PA(passive) AE1 ========= cisco-2 switch (Etherchanel 20)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, passive Firewall will have data plane interfaces down, so there will not be any passing traffic of this port channel until there is failover event.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 06:39:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/594678#M118367</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-08-13T06:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: PA Active/Passive  and Cisco stacking LACP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/594723#M118374</link>
      <description>&lt;P&gt;Great,&lt;/P&gt;
&lt;P&gt;For LACP should be active or Passive ?on cisco and PA,,,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 12:32:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/594723#M118374</guid>
      <dc:creator>K.Mohamed</dc:creator>
      <dc:date>2024-08-13T12:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: PA Active/Passive  and Cisco stacking LACP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/594728#M118375</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/423508891"&gt;@K.Mohamed&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would configure LACP active on PA as well as Cisco side. I would also recommend to enable the&amp;nbsp;LACP pre-negotiation&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/high-availability/ha-concepts/lacp-and-lldp-pre-negotiation-for-activepassive-ha" target="_self"&gt;LACP and LLDP Pre-Negotiation for Active/Passive HA&lt;/A&gt;&amp;nbsp; by selecting check box under: LACP &amp;gt; High Availability Options &amp;gt; Enable in HA Passive State.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 12:43:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/594728#M118375</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-08-13T12:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: PA Active/Passive  and Cisco stacking LACP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/1260989#M126822</link>
      <description>&lt;P&gt;your configuration is incorrect. LACP port-channels (EtherChannel's) use unique ID's or port-channel numbers tied to a unique partner device (a firewall in your case)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so on the cisco side, you need to configure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface Po10&lt;/P&gt;
&lt;P&gt;description - palo firewall1a&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface 1/0/1 ! first cisco switch in the stack&lt;/P&gt;
&lt;P&gt;description - palo firewall1a LACP link 1 of 2&lt;/P&gt;
&lt;P&gt;channel-group 10 mode active ! says run LACP, not PAGP and make the LACP port "Active" or send LACP bpdu's proactively&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface 2/0/1 ! second cisco switch in the stack&lt;/P&gt;
&lt;P&gt;description - palo firewall1a&amp;nbsp; LACP link 2 of 2&lt;/P&gt;
&lt;P&gt;channel-group 10 mode active ! says run LACP, not PAGP and make the LACP port "Active" or send LACP bpdu's proactively&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface Po20&lt;/P&gt;
&lt;P&gt;description - palo firewall1b&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface 1/0/2 ! first cisco switch in the stack&lt;/P&gt;
&lt;P&gt;description - palo firewall1b LACP link 1 of 2&lt;/P&gt;
&lt;P&gt;channel-group 20 mode active ! says run LACP, not PAGP and make the LACP port "Active" or send LACP bpdu's proactively&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface 2/0/2 ! second cisco switch in the stack&lt;/P&gt;
&lt;P&gt;description - palo firewall1b&amp;nbsp; LACP link 2 of 2&lt;/P&gt;
&lt;P&gt;channel-group 20 mode active ! says run LACP, not PAGP and make the LACP port "Active" or send LACP bpdu's proactively&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice the firewall pair is called " firewall1 ", no A or B. and the two firewalls in the pair are called "A" and "B". this implies you have one virtual firewall and two members.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next on the firewalls, you need to connect 2 cables from firewall1a to ports x/0/1. and then 2 cables from firewall1b to ports x/0/2. Notice the difference between ports 1 &amp;amp; 2. On each firewall, those two ports / cables get configured into the same LACP group for each cable bundle of 2.&lt;/P&gt;
&lt;P&gt;firewall1a, ports e1/1 and e1/2 =&amp;gt; go into PO10&lt;/P&gt;
&lt;P&gt;firewall1b, ports e1/1 and e1/2 =&amp;gt; go into PO20&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2026 23:36:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-active-passive-and-cisco-stacking-lacp/m-p/1260989#M126822</guid>
      <dc:creator>anon4all</dc:creator>
      <dc:date>2026-08-04T23:36:29Z</dc:date>
    </item>
  </channel>
</rss>

