<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Same Mac address shared by two paloalto firewalls in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/38325#M28077</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Spot on !!!! Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Sep 2013 13:29:55 GMT</pubDate>
    <dc:creator>DCN</dc:creator>
    <dc:date>2013-09-17T13:29:55Z</dc:date>
    <item>
      <title>Same Mac address shared by two paloalto firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/38322#M28074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I have seen strange behaviour between two palo alto firewalls. &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I have pair of PA-3020 and Pair of PA-500 in Active/standby scenario. They serve two different networks but to provide interconnect between two networks they (Eth 1/3) are connected to Cisco Nexus switch via FEX (VLAN 129). Has anyone seen a case where two different models of the firewall connected via same vlan share same mac address? &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;admin@CFWL02(active)&amp;gt; show arp all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hw address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; status&amp;nbsp;&amp;nbsp; ttl&amp;nbsp; &lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;ethernet1/3.129&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;10.224.63.33&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM style="text-decoration: underline;"&gt;&lt;STRONG&gt;00:1b:17:00:01:12&lt;/STRONG&gt;&lt;/EM&gt; ethernet1/3&amp;nbsp;&amp;nbsp;&amp;nbsp; c&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1487 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@MFWL02(active)&amp;gt; show arp all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hw address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; status&amp;nbsp;&amp;nbsp; ttl&amp;nbsp; &lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;ethernet1/3.129&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;10.224.63.36&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;00:1b:17:00:01:12&lt;/EM&gt;&lt;/SPAN&gt;&lt;/STRONG&gt; ethernet1/3&amp;nbsp;&amp;nbsp;&amp;nbsp; c&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1627 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;L2S01# sh mac address-table vl 129&lt;/P&gt;&lt;P&gt;Legend: &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * - primary entry, G - Gateway MAC, (R) - Routed MAC, O - Overlay MAC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; age - seconds since last seen,+ - primary entry using vPC Peer-Link&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; VLAN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; age&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Secure NTFY&amp;nbsp;&amp;nbsp; Ports/SWID.SSID.LID&lt;/P&gt;&lt;P&gt;---------+-----------------+--------+---------+------+----+------------------&lt;/P&gt;&lt;P&gt;+ 129&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG style="text-decoration: underline;"&gt;&lt;EM&gt;001b.1700.0112&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; F&amp;nbsp;&amp;nbsp;&amp;nbsp; F&amp;nbsp; Po1000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;L2S01# sh mac address-table vl 129&lt;/P&gt;&lt;P&gt;Legend: &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * - primary entry, G - Gateway MAC, (R) - Routed MAC, O - Overlay MAC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; age - seconds since last seen,+ - primary entry using vPC Peer-Link&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; VLAN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; age&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Secure NTFY&amp;nbsp;&amp;nbsp; Ports/SWID.SSID.LID&lt;/P&gt;&lt;P&gt;---------+-----------------+--------+---------+------+----+------------------&lt;/P&gt;&lt;P&gt;* 129&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG style="text-decoration: underline;"&gt;&lt;EM&gt;001b.1700.0112&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic&amp;nbsp;&amp;nbsp; 10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; F&amp;nbsp;&amp;nbsp;&amp;nbsp; F&amp;nbsp; Eth122/1/47&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will appreciate your help if you advise me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;RT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 16:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/38322#M28074</guid>
      <dc:creator>DCN</dc:creator>
      <dc:date>2013-09-13T16:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Same Mac address shared by two paloalto firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/38323#M28075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello good morning, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you mentioned before, both pairs are part of high-availability. Could you please confirm if HA "group ID" also same in both HA environments. If "group-ID" is same for both pairs, there there is s possibility to have an identical virtual MAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5401"&gt;How to Calculate a Virtual MAC Address&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is recommended to have different "group-ID" inside a same network for different HA pair, in order to avoid packet loss.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 16:46:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/38323#M28075</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-09-13T16:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Same Mac address shared by two paloalto firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/38324#M28076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case, you have set Group-ID =1 for both HA pairs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; &lt;/SPAN&gt;&lt;EM style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b; text-decoration: underline;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;00:1b:17:00:01:12&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; ethernet1/3&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 17:09:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/38324#M28076</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-09-13T17:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Same Mac address shared by two paloalto firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/38325#M28077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Spot on !!!! Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Sep 2013 13:29:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/38325#M28077</guid>
      <dc:creator>DCN</dc:creator>
      <dc:date>2013-09-17T13:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Same Mac address shared by two paloalto firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/588498#M117329</link>
      <description>&lt;P&gt;Fyi the link has moved, here is the one that works now in 2024:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXSCA0" target="_blank"&gt;How to Calculate a Virtual MAC Address - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 13:07:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-mac-address-shared-by-two-paloalto-firewalls/m-p/588498#M117329</guid>
      <dc:creator>ksalustro</dc:creator>
      <dc:date>2024-05-31T13:07:25Z</dc:date>
    </item>
  </channel>
</rss>

