<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port Channels in a Active / Passive VWire Environment in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/124244#M46294</link>
    <description>&lt;P&gt;This is a L2 VWire, not a L3 implementation. &amp;nbsp;The Palo Altos sit as a bump-on-the-wire device transparently. &amp;nbsp;They don't participate directly in any port-channel configurations. &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Nov 2016 22:06:57 GMT</pubDate>
    <dc:creator>mlinsemier</dc:creator>
    <dc:date>2016-11-04T22:06:57Z</dc:date>
    <item>
      <title>Port Channels in a Active / Passive VWire Environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/124114#M46278</link>
      <description>&lt;P&gt;We have a couple instances in our environment where we are using VWire where port-channels are located on either side of the Palo Alto device. &amp;nbsp;Also, in this cases, we are running a Palo Alto cluster in Active/Passive HA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In all cases that I have tried, either with LACP (using pre-negotiation) as well as non-LACP (channel mode on), I am unable get any configuration to work. &amp;nbsp;As soon as the second port in the channel comes up on the passive Palo Alto firewall, traffic stops routing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The most simple&amp;nbsp;configuration is this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Cisco 6509 #1 G1/3 ---&amp;gt; Port Channel ( Palo Alto VWire Active ) Port Channel &amp;lt;--- G0/0 Router #1&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Cisco 6509 #1&amp;nbsp;&lt;/SPAN&gt;G2/3 ---&amp;gt; Port Channel&lt;SPAN&gt; ( Palo Alto VWire Passive&amp;nbsp;) Port Channel &lt;/SPAN&gt;&amp;lt;--- G0/1 Router #1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In channel mode on, it appears to the switch&amp;nbsp;that both of the ports are participating in the Port Channel, however obviously only one of them G0/0 is up as the other Palo Alto is in Passive mode (Auto) where the port is brought up but no traffic is forwarding. &amp;nbsp;If i shut down the second port in the Port Channel, traffic begins routing as normal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone here have any expereince with this and is this even feasible in an Active/Passive configuration? &amp;nbsp;I really need that sub second response that you get in a Layer 3 Active / Passive configuration. &amp;nbsp;I have tested channel mode on PAN-OS 7.0.8 and LACP pre-negotiation on PAN-OS 7.1.4h2 both with the same results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 14:49:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/124114#M46278</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2016-11-04T14:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Port Channels in a Active / Passive VWire Environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/124182#M46285</link>
      <description>&lt;P&gt;On gig1/3 and gig2/3, do you have 'no switchport' configured? It almost sounds like bpdus are getting across the HA link and being sent back down the passive link.&lt;/P&gt;&lt;P&gt;Have you done a packet capture on the vwire interface during the port channel failure facing gi2/3 to see if anything is egressing?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 18:14:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/124182#M46285</guid>
      <dc:creator>RFalconer</dc:creator>
      <dc:date>2016-11-04T18:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Port Channels in a Active / Passive VWire Environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/124244#M46294</link>
      <description>&lt;P&gt;This is a L2 VWire, not a L3 implementation. &amp;nbsp;The Palo Altos sit as a bump-on-the-wire device transparently. &amp;nbsp;They don't participate directly in any port-channel configurations. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 22:06:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/124244#M46294</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2016-11-04T22:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Port Channels in a Active / Passive VWire Environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/179377#M55675</link>
      <description>&lt;P&gt;Did you ever get a resolution to this?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2017 14:31:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/179377#M55675</guid>
      <dc:creator>epeeler</dc:creator>
      <dc:date>2017-09-29T14:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: Port Channels in a Active / Passive VWire Environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/179488#M55688</link>
      <description>&lt;P&gt;I too would be interested to know if it is possible to use port-channels as a resilience model in an Active-Passive Palo Alto environment. Does anyone do this, or know whether it is possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Sun, 01 Oct 2017 09:55:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-channels-in-a-active-passive-vwire-environment/m-p/179488#M55688</guid>
      <dc:creator>TomMeadows</dc:creator>
      <dc:date>2017-10-01T09:55:10Z</dc:date>
    </item>
  </channel>
</rss>

