<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active/Active Floating IP/Traffic Forwarding Problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-floating-ip-traffic-forwarding-problem/m-p/1927#M1437</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gonna answer this one myself.&amp;nbsp; After talking with PA support, traffic destined to a Floating IP through it's peer was never designed to go through HA3 packet forwarding.&amp;nbsp; It is assumed that the owner of the Floating IP would always get the traffic first via ARP and the virtual mac.&amp;nbsp; In my situation, I have two /29 that communicate with the upstream ISP routers and I was attempting to use one of my /24 (BGP routed) IPs as a floater.&amp;nbsp; I was wanting to use the Floating IP as a signal point of entry for S2S VPNs.&amp;nbsp; Because of asymmetric routing and BGP, there was no way to guarantee that the Floating IP owner would 100% always receive the packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm working around this issue for now and just using a /30 that is ALWAYS statically routed to one device.&amp;nbsp; But I'm still having IPSec VPN problems, but that's another post. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; Hope this helps someone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Apr 2014 20:30:41 GMT</pubDate>
    <dc:creator>dshue</dc:creator>
    <dc:date>2014-04-07T20:30:41Z</dc:date>
    <item>
      <title>Active/Active Floating IP/Traffic Forwarding Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-floating-ip-traffic-forwarding-problem/m-p/1926#M1436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I have a support case open with PAN but I thought I would query others smarter than I.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;2 x PAN-2020&lt;/LI&gt;&lt;LI&gt;Recently enabled HA Active/Active&lt;/LI&gt;&lt;LI&gt;BGP on External/Currently ONLY Static Inside to Active-Primary device (0.0.0.0/0 -&amp;gt; Active Primary)&lt;/LI&gt;&lt;LI&gt;Session Owner = First Packet (only going to be Active-Primary right now do you static route)&lt;/LI&gt;&lt;LI&gt;Session Setup = IP-modulo&lt;/LI&gt;&lt;LI&gt;Floating IP - x.x.x.128 -&amp;gt; active-secondary preferred&lt;/LI&gt;&lt;LI&gt;Floating IP - x.x.x.129 -&amp;gt; active-primary preferred&lt;/LI&gt;&lt;LI&gt;2 x GlobalProtect Portals - each using respective Floating IPs&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I first noticed an issue when configuring an SSL-portal using a Floating IP.&amp;nbsp; It seems as though only the session owner can communicate with it's preferred floating IP.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example 1:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Client A -&amp;gt; 0.0.0.0/0 -&amp;gt; active-primary -&amp;gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://x.x.x.129"&gt;https://x.x.x.129&lt;/A&gt;&lt;SPAN&gt; = WORKS!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Client A -&amp;gt; 0.0.0.0/0 -&amp;gt; active-primary -&amp;gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://x.x.x.128"&gt;https://x.x.x.128&lt;/A&gt;&lt;SPAN&gt; = FAIL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example 2:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Client A -&amp;gt; 0.0.0.0/0 -&amp;gt; active-secondary -&amp;gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://x.x.x.129"&gt;https://x.x.x.129&lt;/A&gt;&lt;SPAN&gt; = FAIL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Client A -&amp;gt; 0.0.0.0/0 -&amp;gt; active-secondary -&amp;gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://x.x.x.128"&gt;https://x.x.x.128&lt;/A&gt;&lt;SPAN&gt; = WORKS!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From these examples, only the session owner can communicate with its respective floating IP.&amp;nbsp; I have also seen where IPSec tunnels that terminated to ONLY the Active-Primary are having intermittent issues with communicating with internal hosts.&amp;nbsp; All outbound and inbound NAT'd traffic seems to be doing wonderfully, just sessions that terminate to the firewalls themselves seem to be having issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a drawing that I can share if anyone shows interest in helping me troubleshoot.&amp;nbsp; I'm at a loss and been at if for 4 days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Mar 2014 15:38:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-floating-ip-traffic-forwarding-problem/m-p/1926#M1436</guid>
      <dc:creator>dshue</dc:creator>
      <dc:date>2014-03-26T15:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Active Floating IP/Traffic Forwarding Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-floating-ip-traffic-forwarding-problem/m-p/1927#M1437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gonna answer this one myself.&amp;nbsp; After talking with PA support, traffic destined to a Floating IP through it's peer was never designed to go through HA3 packet forwarding.&amp;nbsp; It is assumed that the owner of the Floating IP would always get the traffic first via ARP and the virtual mac.&amp;nbsp; In my situation, I have two /29 that communicate with the upstream ISP routers and I was attempting to use one of my /24 (BGP routed) IPs as a floater.&amp;nbsp; I was wanting to use the Floating IP as a signal point of entry for S2S VPNs.&amp;nbsp; Because of asymmetric routing and BGP, there was no way to guarantee that the Floating IP owner would 100% always receive the packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm working around this issue for now and just using a /30 that is ALWAYS statically routed to one device.&amp;nbsp; But I'm still having IPSec VPN problems, but that's another post. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; Hope this helps someone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Apr 2014 20:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-floating-ip-traffic-forwarding-problem/m-p/1927#M1437</guid>
      <dc:creator>dshue</dc:creator>
      <dc:date>2014-04-07T20:30:41Z</dc:date>
    </item>
  </channel>
</rss>

