<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: wan interface configuration for HA active/passive in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-configuration-for-ha-active-passive/m-p/79174#M43184</link>
    <description>&lt;P&gt;Pankaj,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's what I thought, but I tried moving the existing firewall to that setup, moved isp, and PA to switch on same vlan with access ports, and they wouldn't talk. &amp;nbsp;Only had a brief downtime window last weekend to test so wasn't able to do much troubleshooting. &amp;nbsp;This next weekend is the planned implementation for new pair so I'll try again, and have time to clear arp and track down any issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the help everyone.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jun 2016 13:05:31 GMT</pubDate>
    <dc:creator>travisj</dc:creator>
    <dc:date>2016-06-06T13:05:31Z</dc:date>
    <item>
      <title>wan interface configuration for HA active/passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-configuration-for-ha-active-passive/m-p/79103#M43151</link>
      <description>&lt;P&gt;We are about to replace a single 2050 with an HA pair of 3050's. &amp;nbsp; Having some trouble figuring out how to get the switch and Pa configured so I can share the single ISP connection with both firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Current setup has interface 1/3 as L3 with the WAN ip address&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was trying to minimize the changes to make (because 2050 is insanely slow to commit) so attempted using a new vlan 111 on our core switch, set it up on two ports in access mode (untag all) and tried moving the ISP router and the palo alto wan interface into the switch on those two ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I going to need to change the wan interface on the palo alto to have a tagged sub interface on vlan 111 and move the wan IP addresses to it? &amp;nbsp; Hopefully I'm just missing something simple.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2016 17:08:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-configuration-for-ha-active-passive/m-p/79103#M43151</guid>
      <dc:creator>travisj</dc:creator>
      <dc:date>2016-06-04T17:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: wan interface configuration for HA active/passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-configuration-for-ha-active-passive/m-p/79105#M43153</link>
      <description>&lt;P&gt;You should create subinterfaces on palo only if it connects to switch trunk port.&lt;/P&gt;
&lt;P&gt;If switch port is access then you don't use subinterfaces.&lt;/P&gt;
&lt;P&gt;If you set up HA then interface mac addresses will change and Palo will send graditious arp out only to notify interface ip change but not for DNAT ip addresses so you should be ready to clear switch arp cache.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2016 19:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-configuration-for-ha-active-passive/m-p/79105#M43153</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-04T19:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: wan interface configuration for HA active/passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-configuration-for-ha-active-passive/m-p/79134#M43168</link>
      <description>&lt;P&gt;You have to move ISP link to switch. On switch there should be three ports and these three ports should be part of same VLAN, access ports. One port for ISP, One for active firewall and one for passive firewall that's it.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2016 13:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-configuration-for-ha-active-passive/m-p/79134#M43168</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-06-05T13:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: wan interface configuration for HA active/passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-configuration-for-ha-active-passive/m-p/79174#M43184</link>
      <description>&lt;P&gt;Pankaj,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's what I thought, but I tried moving the existing firewall to that setup, moved isp, and PA to switch on same vlan with access ports, and they wouldn't talk. &amp;nbsp;Only had a brief downtime window last weekend to test so wasn't able to do much troubleshooting. &amp;nbsp;This next weekend is the planned implementation for new pair so I'll try again, and have time to clear arp and track down any issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the help everyone.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 13:05:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-configuration-for-ha-active-passive/m-p/79174#M43184</guid>
      <dc:creator>travisj</dc:creator>
      <dc:date>2016-06-06T13:05:31Z</dc:date>
    </item>
  </channel>
</rss>

