<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connecting a Tier 1 firewall pair to a Tier 2 firewall pair without a switch in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/connecting-a-tier-1-firewall-pair-to-a-tier-2-firewall-pair/m-p/21335#M15570</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Internet&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;Tier 1 FW&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;Tier 2 FW (Palo Alto Firewall) in Active/Passive mode&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;Core Switch (HA)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I connect a pair of Tier 2 firewalls (A/P HA) to a Tier 1 firewall pair (A/P HA) without using a switch(s) in between? there will be 2 UTP from each T1 firewall - 1 to each Palo Alto Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the main reason is that there's no available switches for the network.&lt;/P&gt;&lt;P&gt;technically will this work? is there any impact to the cluster?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Aug 2012 19:25:03 GMT</pubDate>
    <dc:creator>afiq</dc:creator>
    <dc:date>2012-08-07T19:25:03Z</dc:date>
    <item>
      <title>Connecting a Tier 1 firewall pair to a Tier 2 firewall pair without a switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connecting-a-tier-1-firewall-pair-to-a-tier-2-firewall-pair/m-p/21335#M15570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Internet&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;Tier 1 FW&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;Tier 2 FW (Palo Alto Firewall) in Active/Passive mode&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;Core Switch (HA)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I connect a pair of Tier 2 firewalls (A/P HA) to a Tier 1 firewall pair (A/P HA) without using a switch(s) in between? there will be 2 UTP from each T1 firewall - 1 to each Palo Alto Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the main reason is that there's no available switches for the network.&lt;/P&gt;&lt;P&gt;technically will this work? is there any impact to the cluster?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Aug 2012 19:25:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connecting-a-tier-1-firewall-pair-to-a-tier-2-firewall-pair/m-p/21335#M15570</guid>
      <dc:creator>afiq</dc:creator>
      <dc:date>2012-08-07T19:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting a Tier 1 firewall pair to a Tier 2 firewall pair without a switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connecting-a-tier-1-firewall-pair-to-a-tier-2-firewall-pair/m-p/21336#M15571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anyone having similar running setup in their datacenter?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2012 01:05:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connecting-a-tier-1-firewall-pair-to-a-tier-2-firewall-pair/m-p/21336#M15571</guid>
      <dc:creator>afiq</dc:creator>
      <dc:date>2012-08-08T01:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting a Tier 1 firewall pair to a Tier 2 firewall pair without a switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connecting-a-tier-1-firewall-pair-to-a-tier-2-firewall-pair/m-p/21337#M15572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume when you say UTP, you mean that both active and passive Tier 2 Palo firewalls will each have a ethernet uplink (CAT5e) to the Tier 1 firewalls?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order for this to work, the uplinks of the Active/Passive Tier 2 firewall cluster which would be placed downstream of the Tier 1 firewall cluster would need to be connected to layer 2 ports which share the same state table on the corresponding upstream Tier 1 firewall (that is....the same ARP and MAC table). &lt;/P&gt;&lt;P&gt;This would be required for HA transition to operate on the Tier 2 firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess it depends on what kind of firewalls the Tier 1 are it may work...if you have Cisco ASAs for example, you might be able to use two layer 2 switch ports to uplink to the Tier 2 firewalls. Or other vendor firewalls might let you put those ports into some kind of layer 2, pass-through mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No guarantees here without lab testing though...this is theoretical.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2012 03:05:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connecting-a-tier-1-firewall-pair-to-a-tier-2-firewall-pair/m-p/21337#M15572</guid>
      <dc:creator>panman</dc:creator>
      <dc:date>2012-08-08T03:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting a Tier 1 firewall pair to a Tier 2 firewall pair without a switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connecting-a-tier-1-firewall-pair-to-a-tier-2-firewall-pair/m-p/21338#M15573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are docs in the documentation area on how to setup two ISP's at once - this would be similar setup (see TFW1 as "ISP1" and TFW2 as "ISP2").&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PA cluster must "ping" each uplink to determine which way is functional.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However in order for this to work without switches in between you need to do a manual full-mesh.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Meaning PA1 is connected with one (or more) wires to TFW1 and with one (or more) wires to TFW2. Where PA2 have the same setup - otherwise you might end up with PA1 is dead so PA2 became active but TFW1 is still active and TFW2 is passive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As already mentioned you wont need this full-mesh if the passive unit of TFW cluster acts as a L2-device (similar to how HSRP/VRRP works).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another method is to setup PA as active-active cluster or two single boxes (however the later will most likely demand some sort of loadbalancing before the PA cluster so a specific client will use a specific PA on its way out in order to keep logs in a sane way but also for the appid and flows and stuff in PA to work properly).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also use PA-cluster as VWIRE (without active/passive failover) to avoid routing/pbf headache &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2012 22:06:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connecting-a-tier-1-firewall-pair-to-a-tier-2-firewall-pair/m-p/21338#M15573</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-08-20T22:06:34Z</dc:date>
    </item>
  </channel>
</rss>

