<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LACP and HA pair in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-and-ha-pair/m-p/33161#M24306</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't need the secondary device interfaces to be up, I'm only looking for the correct configuration to make the secondary device work during a fail over with the outside device over LACP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've read those design guides, but they seem to skip many Layer-2 scenarios and were written pre-LACP support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically when I have the PA primary/secondary connected to separate AE's on an outside device, HA works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this one situation I have the PA primary/secondary connected to separate interfaces on the same AE of the outside device, and the HA failed.&amp;nbsp; I need to find out if it's a valid setup and configuration, or if LACP won't work and I have to change it to a non-LACP LAG.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Mar 2015 13:10:53 GMT</pubDate>
    <dc:creator>davis@udel.edu</dc:creator>
    <dc:date>2015-03-24T13:10:53Z</dc:date>
    <item>
      <title>LACP and HA pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-and-ha-pair/m-p/33159#M24304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My tested design has been to LACP between the same LAG (i.e. AE0) on the PA primary and secondary units, to different LAG entries (ie. AE0, AE1) on the outside and inside equipment (Both Juniper).&amp;nbsp; I have one device though (Juniper SRX) that has VPN tunnel terminations on it that have to be declared as the end-points, so I can't use different LAG entries to each of the Primary and Secondary PA.&amp;nbsp; So I put the Primary and Secondary PA connection points (AE0) into the same LAG (AE0) on the Juniper SRX under LACP and it runs with just the single connection ok.&amp;nbsp;&amp;nbsp; BUT, I tested the HA failover and the secondary PA failed to establish the LACP connection with the Juniper SRX and faulted the link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I attach a HA pair of PA's to a single device if LACP isn't going to work?&amp;nbsp; Is this a bug or do I need to not run LACP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2015-03-19T06:49:50-04:00 10.10.24.201 fw user.crit 1,2015/03/19 06:49:50,007801001168,SYSTEM,lacp,0,2015/03/19 06:49:50,,unresponsive,ethernet1/3,0,0,general,critical,LACP interface ethernet1/3 moved out of AE-group ae4(peer is not responding to new LACP connection),90118,0x8000000000000000&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Mar 2015 14:30:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-and-ha-pair/m-p/33159#M24304</guid>
      <dc:creator>davis@udel.edu</dc:creator>
      <dc:date>2015-03-19T14:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: LACP and HA pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-and-ha-pair/m-p/33160#M24305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On a secondary device in an Active/Passive cluster all the interfaces are "down" and do not pass any traffic until they become the active node.&amp;nbsp; If your design requires that the secondary interfaces be up, then you will need to use an Active/Active design and be careful about creating layer 2 loops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you seen the reference design for using Active/Passive Palo Alto firewalls with AE bundles?&lt;/P&gt;&lt;P&gt;this is found on page 80 and following in the design guide.&amp;nbsp; This may be what you are looking for in your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2561"&gt;Designing Networks with Palo Alto Networks Firewalls&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2560"&gt;Diagrams and Tested Configurations&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2015 12:38:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-and-ha-pair/m-p/33160#M24305</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-03-22T12:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: LACP and HA pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-and-ha-pair/m-p/33161#M24306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't need the secondary device interfaces to be up, I'm only looking for the correct configuration to make the secondary device work during a fail over with the outside device over LACP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've read those design guides, but they seem to skip many Layer-2 scenarios and were written pre-LACP support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically when I have the PA primary/secondary connected to separate AE's on an outside device, HA works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this one situation I have the PA primary/secondary connected to separate interfaces on the same AE of the outside device, and the HA failed.&amp;nbsp; I need to find out if it's a valid setup and configuration, or if LACP won't work and I have to change it to a non-LACP LAG.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Mar 2015 13:10:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-and-ha-pair/m-p/33161#M24306</guid>
      <dc:creator>davis@udel.edu</dc:creator>
      <dc:date>2015-03-24T13:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: LACP and HA pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-and-ha-pair/m-p/33162#M24307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I eventually found this document on LACP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/networking/lacp-settings.html"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/networking/lacp-settings.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the very last paragraph listed this statement which worked in my scenario and allowed the single SRX&lt;/P&gt;&lt;P&gt;tunnel to be LACP'd across both primary and secondary PA HA devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 14px;"&gt;When the LACP peers (also in HA mode) are virtualized (appearing to the network as a single device), selecting the &lt;/SPAN&gt;Same System MAC Address for Active-Passive HA&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 14px;"&gt; option for the firewalls is a best practice to minimize latency during failover&lt;/SPAN&gt;"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2015 14:22:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-and-ha-pair/m-p/33162#M24307</guid>
      <dc:creator>davis@udel.edu</dc:creator>
      <dc:date>2015-04-09T14:22:27Z</dc:date>
    </item>
  </channel>
</rss>

