<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change HA from A/A to A/P - techniques and known issues? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34097#M25008</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would always go with Active/Passive unless you have one of the specific use cases for Active/Active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the main configuration change will be the removal of HA3 as a link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you are already running single device the cut should be relatively painless.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Mar 2015 20:46:04 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2015-03-18T20:46:04Z</dc:date>
    <item>
      <title>Change HA from A/A to A/P - techniques and known issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34095#M25006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have two PA-500's in Active/Active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do not need to have them in A/A (in hindsight, it was a mistake) because we do not use asynchronous routing or meet the other typical A/A criteria. I think we are paying for that mistake, as you'll read below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When running software 6.0.5 I implemented a site-to-site VPN through which I ran a client-server application over a specific port. After 10-30 minutes the port would close, cutting off the application link. I opened a case with PA, got logs from the firewalls and wireshark captures from the client. While PA was researching the issue, I asked PA if perhaps upgrading to 6.1.2 would fix the problem. They agreed we could try (no guarantees, of course).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We upgraded, and found that when running 6.1.2 in Active/Active, the Active-Secondary could not refresh ARP. The secondary would hold it's ARP table for the timeout period (1800 seconds - 30 minutes), then fail - which caused our Internet connection to be unstable (pinging a device on the Internet would result in 8 packets successful, then 8 dropped, then 12 successful, then 12 dropped, and so on). We now have a separate ticket with PA on this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As an experimental effort to solve the ARP problem, we suspended the Active-Secondary device, and since then - running only 1 firewall - our Internet connection is perfectly stable AND the VPN functions flawlessly. The application runs over the VPN without any drops/disconnections. I did share this discovery with PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So...I'm now wondering if simply changing from Active-Active to Active-Passive (staying with 6.1.2) might solve both the VPN and ARP issue. I recall reading about an ARP issue with an earlier 6.x version of software, but I think that got fixed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you think about us switching from A/A to A/P? Any problems with changing from A/A to A/P? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we switch, is it a matter of changing the setup from active-active mode active-passive by changing the Active-Primary to Active-Passive (device ID 0) and the Active-Secondary to Active Passive (device ID 1)? We already have control links and election settings established, and I'm wondering if those will stay the same - or if I have to reconfigure everything as though I were adding a new firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Mar 2015 19:23:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34095#M25006</guid>
      <dc:creator>MikeBowler</dc:creator>
      <dc:date>2015-03-18T19:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Change HA from A/A to A/P - techniques and known issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34096#M25007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mikebowler,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will not directly answer your question, but will provide some details on active/active vs. active/passive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-8272"&gt;HA Active Active vs Active Passive.pptx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please do not forget to mark and 'Helpful' or 'Correct' replies.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Mar 2015 20:27:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34096#M25007</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-03-18T20:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Change HA from A/A to A/P - techniques and known issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34097#M25008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would always go with Active/Passive unless you have one of the specific use cases for Active/Active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the main configuration change will be the removal of HA3 as a link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you are already running single device the cut should be relatively painless.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Mar 2015 20:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34097#M25008</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-03-18T20:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Change HA from A/A to A/P - techniques and known issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34098#M25009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you both!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Mar 2015 16:46:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34098#M25009</guid>
      <dc:creator>MikeBowler</dc:creator>
      <dc:date>2015-03-19T16:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: Change HA from A/A to A/P - techniques and known issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34099#M25010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We did the upgrade - from A/A to A/P - a few weeks back and all is well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both the VPN and ARP issues have disappeared, and the connection world is at peace (well, it is here anyway...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect A/A brings some complications to the table that PA is not completely able to manage, but our A/P configuration is solid and we are, once again, happy campers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2015 16:26:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34099#M25010</guid>
      <dc:creator>MikeBowler</dc:creator>
      <dc:date>2015-04-16T16:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Change HA from A/A to A/P - techniques and known issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34100#M25011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad things went well for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, Active/Active does bring complications and design considerations.&amp;nbsp; I manage four A/A clusters in the data center.&amp;nbsp; But there are situations where it is required.&amp;nbsp; The trick is not to over complicate the situation unnecessarily.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to close the loop here is the Active/Active technote reviewing the issues to watch in the A/A deploy.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2541"&gt;Configuring Active/Active HA PAN-OS 4.0&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2015 20:58:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ha-from-a-a-to-a-p-techniques-and-known-issues/m-p/34100#M25011</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-04-16T20:58:05Z</dc:date>
    </item>
  </channel>
</rss>

