<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: arp issue with PA Active/Active in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issue-with-pa-active-active/m-p/156389#M51332</link>
    <description>&lt;P&gt;This is a pretty common issue in an Active/Active configuration and there are a lot of potential problems that you could be hitting; this type of thing is why Active/Active configuration is really not advised unless you are doing a large amount of async routing.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 May 2017 13:19:17 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-05-12T13:19:17Z</dc:date>
    <item>
      <title>arp issue with PA Active/Active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issue-with-pa-active-active/m-p/156294#M51305</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 PA-3060's, setup in Active / active&lt;/P&gt;&lt;P&gt;I have a vlan 213 with 10.172.213.0/24 assigned to it&lt;/P&gt;&lt;P&gt;I have .2 and .3 assigned to the PA's and .1 assigned as a HA Virtual ip .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also have 3 virtual machines, app1 app2 app3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;app1 and app3 can arp 10.172.213.1, app2 can't&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;these vm's are on the same host, and a few hours ago app2 could arp .1 (DGW).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;last time I fixed it by rebooting both PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also I have tried (and it worked), but shutting down the Active state of each PA one by one and letting things fail over .. so shutdown pa1 wait then turn on pa1 and turn off pa2 and wait and then turn on pa2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I diagnose this problem ??&lt;/P&gt;&lt;P&gt;What am I missing ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 21:08:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-issue-with-pa-active-active/m-p/156294#M51305</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-05-11T21:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: arp issue with PA Active/Active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issue-with-pa-active-active/m-p/156389#M51332</link>
      <description>&lt;P&gt;This is a pretty common issue in an Active/Active configuration and there are a lot of potential problems that you could be hitting; this type of thing is why Active/Active configuration is really not advised unless you are doing a large amount of async routing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 13:19:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-issue-with-pa-active-active/m-p/156389#M51332</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-12T13:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: arp issue with PA Active/Active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issue-with-pa-active-active/m-p/156497#M51384</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okay, I can accept Active/Active is complicated. &amp;nbsp;What I can't accept it that it just broken. if it work for big environments then it should work for all environments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because this is a trial, I want to investigate what the issue is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have done packet captures on both pa's and I can see the arp request is being dropped by both PA's ??? &amp;nbsp;thats very strange&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is a common issue, then maybe the PA's are not for me. this seems like a fairly standard easy setup. My Aristra switches can do vrrp across 2 nodes for a distributed DGW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;When I disable one pa1 from the active active setup it all works fine..&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 23:06:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-issue-with-pa-active-active/m-p/156497#M51384</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-05-12T23:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: arp issue with PA Active/Active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issue-with-pa-active-active/m-p/157110#M51561</link>
      <description>&lt;P&gt;Its an interaction between OSPF and active active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The primary PA inserts a /32 into the routing table so it is the only device that responds to pings but OSPF takes that and redistributes it to the other PA, once that OSPF route is in the table it stops responding to arp’s !!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Solution I have to filter out all the VIP address from &amp;nbsp;OSPF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting ....&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 06:31:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-issue-with-pa-active-active/m-p/157110#M51561</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-05-18T06:31:40Z</dc:date>
    </item>
  </channel>
</rss>

