<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA in active-active mode and Cluster ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-in-active-active-mode-and-cluster-id/m-p/25378#M18493</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andreas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the clusterID is what is used to announce cluster membership, so if both clusters have the same ID and reside on the same networks/VLANs this could potentially cause the wrong members to join a cluster. Please make sure to give each cluster a unique cluster ID so peers can't join the wrong cluster&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Jan 2012 17:13:42 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2012-01-30T17:13:42Z</dc:date>
    <item>
      <title>PA in active-active mode and Cluster ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-in-active-active-mode-and-cluster-id/m-p/25377#M18492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;we ran into a strange problem tonight.&lt;/P&gt;&lt;P&gt;We are running PA 4.0.8 in active/active because me might encounter asymmetric routing.&lt;/P&gt;&lt;P&gt;We have two A/A clusters in different data centers. Both clusters have the same cluster ID.&lt;/P&gt;&lt;P&gt;The traffic is going only over one cluster by design. We checked the traffic counters on the routers and confirmed that only one site is seeing traffic, BUT, the strange thing is that I saw traffic logs in the passive DC cluster.&lt;/P&gt;&lt;P&gt;At the same time the traffic crossing the PAs was very slow or not working at all.&lt;/P&gt;&lt;P&gt;Could it be that somehow the session information is forwarded to another cluster if it has the same cluster ID?&lt;/P&gt;&lt;P&gt;After disabling HA3 the problem went away and I don't see anything anymore in the traffic logs on the passive cluster.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Jan 2012 00:56:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-in-active-active-mode-and-cluster-id/m-p/25377#M18492</guid>
      <dc:creator>AndreasB</dc:creator>
      <dc:date>2012-01-29T00:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: PA in active-active mode and Cluster ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-in-active-active-mode-and-cluster-id/m-p/25378#M18493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andreas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the clusterID is what is used to announce cluster membership, so if both clusters have the same ID and reside on the same networks/VLANs this could potentially cause the wrong members to join a cluster. Please make sure to give each cluster a unique cluster ID so peers can't join the wrong cluster&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jan 2012 17:13:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-in-active-active-mode-and-cluster-id/m-p/25378#M18493</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2012-01-30T17:13:42Z</dc:date>
    </item>
  </channel>
</rss>

