<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A/P HA with more than 1 passive unit in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22746#M16629</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shanon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Another passive Member - Is not possible.&lt;/P&gt;&lt;P&gt;2. If both units goes down then it turns active - It is not possible.&lt;/P&gt;&lt;P&gt;3. Basically it should do routing if both the boxes fail - This is possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have to configure something like IP monitor on Internet CPE router. If both the units are down than send traffic to third unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This third unit is independent of HA cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have additional query on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Oct 2014 22:09:15 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2014-10-07T22:09:15Z</dc:date>
    <item>
      <title>A/P HA with more than 1 passive unit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22739#M16622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a customer looking to extend their DR capability to a 2nd physical site (Site B).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently they have 2 PAN 3050 firewalls in an A/P cluster at Site A. As the new site will be connected via fibre we will split the cluster across both sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Site B will very much be a cold standby site with no production load under normal conditions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would like to still maintain PAN device redundancy at Site A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is it possible to leave the existing cluster as is at Site A, and add a 3rd unit to the cluster at Site B? &lt;/LI&gt;&lt;LI&gt;How would this be achieved (using spare ports on the dataplane)? &lt;/LI&gt;&lt;LI&gt;Is it recommended/not recommended?&lt;/LI&gt;&lt;LI&gt;What other considerations should we be aware of?&lt;/LI&gt;&lt;LI&gt;How would this impact on "split brain" type scenarios of the link between the sites was lost?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate any answers, feedback and personal experience in this type of scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Shannon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 19:20:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22739#M16622</guid>
      <dc:creator>Shannon-Rowe</dc:creator>
      <dc:date>2014-10-07T19:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: A/P HA with more than 1 passive unit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22740#M16623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shannon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is currently not supported but we do have a feature request for it. You can mention FR 1043 to your sales/system engineer. He/She can vote on your behalf. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 19:22:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22740#M16623</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-10-07T19:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: A/P HA with more than 1 passive unit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22741#M16624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/29561"&gt;Shannon-Rowe&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think you cannot have three units as a part of cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will suggest running OSPF with the route SiteB as a lower metric, so in case SiteA goes down it fails over to SIteB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 19:24:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22741#M16624</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-07T19:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: A/P HA with more than 1 passive unit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22742#M16625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shannon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Samir suggest as of now its not possible to add third unit in HA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would it be possible to provide us rough network dia. That way we might be able to suggest any other work around.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 19:26:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22742#M16625</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-07T19:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: A/P HA with more than 1 passive unit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22743#M16626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answers. A very high level, sanitized diagram below. Ideally we would have 2 units at the production datacentre.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to have an independent unit at the standby unit, and somehow script regular config restores to the standby datacentre; this would also require having all dataplane interfaces shutdown, and could get messy, I realise, just want to explore all options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Shannon&lt;/P&gt;&lt;P&gt;&lt;IMG alt="DR Diagrams v0.2.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16110_DR Diagrams v0.2.jpg" style="height: 380px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 19:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22743#M16626</guid>
      <dc:creator>Shannon-Rowe</dc:creator>
      <dc:date>2014-10-07T19:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: A/P HA with more than 1 passive unit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22744#M16627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shannon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How would you use one more firewall in "standby Data center".&lt;/P&gt;&lt;P&gt;1. What routing functinoality it will do?&lt;/P&gt;&lt;P&gt;2. When it should be active?&lt;/P&gt;&lt;P&gt;3. What traffic it will pass.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 20:11:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22744#M16627</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-07T20:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: A/P HA with more than 1 passive unit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22745#M16628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;1. What routing functionality it will do? - The intent would be for it to be another passive member of the cluster&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;2. When it should be active? - if both units at the production unit were to fail, or the production facility were to be completely compromised&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;3. What traffic it will pass. - only HA sync traffic. in conjunction with the ISP and BGP routing (not on the PAN), network border IP addressing would be assumed in the event of #2 being realized.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 21:08:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22745#M16628</guid>
      <dc:creator>Shannon-Rowe</dc:creator>
      <dc:date>2014-10-07T21:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: A/P HA with more than 1 passive unit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22746#M16629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shanon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Another passive Member - Is not possible.&lt;/P&gt;&lt;P&gt;2. If both units goes down then it turns active - It is not possible.&lt;/P&gt;&lt;P&gt;3. Basically it should do routing if both the boxes fail - This is possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have to configure something like IP monitor on Internet CPE router. If both the units are down than send traffic to third unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This third unit is independent of HA cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have additional query on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 22:09:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-p-ha-with-more-than-1-passive-unit/m-p/22746#M16629</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-07T22:09:15Z</dc:date>
    </item>
  </channel>
</rss>

