<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HA PANs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153262#M50616</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to design a new solution in our network infrastructure. Here's are the requirements:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- &amp;nbsp;Single ISP -- Two active Internet circutis --- (Corrected from Two ISPs to a single ISP)&lt;BR /&gt;- &amp;nbsp;Current topology: Two Internet circutis connected to two cisco edge routers in active/active mode, both circuts are used.&lt;BR /&gt;- &amp;nbsp;Two core switches: Two core switches connected to the two edge routers in active/active mode.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Two HA PANs behind the two core switches.&lt;BR /&gt;- &amp;nbsp;Goal: Move the two HA PANs in front of the two edge routers.&lt;BR /&gt;&lt;BR /&gt;Questions: Since the HA PANs are in Active/Passive mode this means that we can't connect the two Internet circuits directly to the HA PANs to acheive Active/Active links to the Internet? Is this correct? If so, does that mean we will need another pair of HA PANs to be able to connect the two Internet circuits to each HA pair?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advnace.&lt;/P&gt;&lt;P&gt;Best, ~sK&lt;/P&gt;</description>
    <pubDate>Wed, 19 Apr 2017 21:28:47 GMT</pubDate>
    <dc:creator>Sadik_Khirbash</dc:creator>
    <dc:date>2017-04-19T21:28:47Z</dc:date>
    <item>
      <title>HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153262#M50616</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to design a new solution in our network infrastructure. Here's are the requirements:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- &amp;nbsp;Single ISP -- Two active Internet circutis --- (Corrected from Two ISPs to a single ISP)&lt;BR /&gt;- &amp;nbsp;Current topology: Two Internet circutis connected to two cisco edge routers in active/active mode, both circuts are used.&lt;BR /&gt;- &amp;nbsp;Two core switches: Two core switches connected to the two edge routers in active/active mode.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Two HA PANs behind the two core switches.&lt;BR /&gt;- &amp;nbsp;Goal: Move the two HA PANs in front of the two edge routers.&lt;BR /&gt;&lt;BR /&gt;Questions: Since the HA PANs are in Active/Passive mode this means that we can't connect the two Internet circuits directly to the HA PANs to acheive Active/Active links to the Internet? Is this correct? If so, does that mean we will need another pair of HA PANs to be able to connect the two Internet circuits to each HA pair?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advnace.&lt;/P&gt;&lt;P&gt;Best, ~sK&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 21:28:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153262#M50616</guid>
      <dc:creator>Sadik_Khirbash</dc:creator>
      <dc:date>2017-04-19T21:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153269#M50617</link>
      <description>&lt;P&gt;It's not an answer to your question, but why are you wanting to put the firewalls in-front of your edge routers?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 20:15:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153269#M50617</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-04-19T20:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153271#M50619</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48414"&gt;@Sadik_Khirbash&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;...&lt;BR /&gt;Questions: Since the HA PANs are in Active/Passive mode this means that we can't connect the two Internet circuits directly to the HA PANs to acheive Active/Active links to the Internet? Is this correct? If so, does that mean we will need another pair of HA PANs to be able to connect the two Internet circuits to each HA pair?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advnace.&lt;/P&gt;&lt;P&gt;Best, ~sK&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;In an A/P deployment the operational interfaces on the P FW are disabled so you wouldn't be able to land one of your ISP connections on your secondary. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've never done A/A, but based upon what I know, if you deploy a single A/A pair you could deploy a single FW pair connecting an ISPs into a FW. &amp;nbsp;(If one FW failed at least you'd still maintain connectivity)&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 20:22:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153271#M50619</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-04-19T20:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153272#M50620</link>
      <description>&lt;P&gt;Sorry... Just made the correction. The PANs aren't sitting in fron of the edge router. They are sitting behind the core routers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;~sK&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 20:22:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153272#M50620</guid>
      <dc:creator>Sadik_Khirbash</dc:creator>
      <dc:date>2017-04-19T20:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153280#M50621</link>
      <description>&lt;P&gt;I guess I'm not following. &amp;nbsp;What is the end location you're wanting your FWs to exist at?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is very a level view of a potential network (Leaving out a DMZ and a fair amount of potential switches)...Youre saying that currently your firewalls sit between that last link (between your core routers and your internal LAN?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="High Level.png" style="width: 496px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8866iDCC13F1D608635D3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="High Level.png" alt="High Level.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 20:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153280#M50621</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-04-19T20:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153286#M50623</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm considering the following deployment where there's only one A/A pair. &amp;nbsp;I hope this design will work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&amp;nbsp; &amp;nbsp; &lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ISP_01 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/STRONG&gt; &amp;nbsp;&lt;/U&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; ^ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ^&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; v &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;v&lt;/P&gt;&lt;P&gt;Edge_Rtr_01 &amp;nbsp; &amp;lt;-----------&amp;gt; &amp;nbsp;Edge_Rtr_02&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; ^ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ^ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ^ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ^&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;\ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|&lt;/P&gt;&lt;P&gt;A/PAN &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;lt;-----------&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; A/PAN&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; ^ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;^ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ^ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;^&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; \ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|&lt;/P&gt;&lt;P&gt;Core_01 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;lt;-----------&amp;gt; &amp;nbsp; Core_01&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 21:12:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153286#M50623</guid>
      <dc:creator>Sadik_Khirbash</dc:creator>
      <dc:date>2017-04-19T21:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153289#M50626</link>
      <description>&lt;P&gt;if I am understanding the question, we can actually simplify it to a single ISP. I mean basically you want each firewall to be able to leverage having two available ISPs, correct? in that case, your approach would be the same as asking how you would configure a single ISP to work with a firewall pair in HA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and I believe the response would be to have an intermediate switch (or two depending on your desire for switch HA), so that the ISP is plugged into one port and each PA is plugged into another port (for a total of 3), and then just scale that up for 2 ISPs (likely private VLANs on the switch for each set of 3 ports).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if that makes sense. i've had a day, so my brain is fried anyway. that's my excuse.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ETA: You will be warned and very well educated to try to avoid putting PA in active/active unless absolutely mandatory, such as in the case of resolving asymetric routing issues.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 21:20:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153289#M50626</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-19T21:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153319#M50631</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/58582"&gt;@bradk14&lt;/a&gt;&amp;nbsp;Not trying to answer for&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48414"&gt;@Sadik_Khirbash&lt;/a&gt;&amp;nbsp;but keeping two ISPs allows for vendor diversity...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my deployment we've actually got 3 independent ISPs on wholly diverse paths. &amp;nbsp;That come into my company. &amp;nbsp;Maybe it's over-kill but hey...at least we can say we've got redundancy. &amp;nbsp;lol&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 02:34:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153319#M50631</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-04-20T02:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153369#M50646</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;apologies if my point wasn't clear. I'm not disparaging or questioning the use of multiple providers, I was just trying to streamline the question. Whether you have 1, 2, 3 or 5 or more ISPs, the process should be the same. You shouldn't have to rely on each PA in an HA pair to be responsible for a single ISP connection, especially when you are setting out to have an Active/Active configuration just to accomplish it. The process should be the same for as many external connections as you may have and that's to use that switch before the firewall to be able to 'split' the connections and leave the passive firewall's ports disabled.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 13:45:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153369#M50646</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-20T13:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153389#M50649</link>
      <description>&lt;P&gt;Agreed...How you described it before (I think it was you) is how we're doing it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Those 3 edge routers have connection points into switch(s) and our single HA-pair sits between those ISPs. &amp;nbsp;Negating the need for 3 stand-alone HA pairs.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 16:20:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153389#M50649</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-04-20T16:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: HA PANs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153617#M50698</link>
      <description>&lt;P&gt;I deal with this by having an additional pair of switches between the Palos and Routers. I use HSRP on the switches for failover. if a circuit fails, the active PA can still find the route to whichever router is active. The Routers and the PAs all sit on the same vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The routers themselves are using BGP with our registered AS number and multiple prepends to create a prefered route out our primary ISP. To handle a failure deeper in the ISP, but not at our local link, I use SLAs on the routers to shut down the BGP neighbour, which will force a cutover to my backup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the routers inside interfaces, I create a subinterface using HSRP so each router uses the same gateway IP, so no matter which router is active, the same gateway IP is responding.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This allows you to use Active/Passive in your config.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 13:15:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pans/m-p/153617#M50698</guid>
      <dc:creator>cengasser</dc:creator>
      <dc:date>2017-04-21T13:15:10Z</dc:date>
    </item>
  </channel>
</rss>

