<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Edge Firewall Design in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193176#M57941</link>
    <description>&lt;P&gt;&lt;SPAN&gt;I am trying to design the edge firewall and core network currently and I have a core Layer not in a "stack" or "&lt;/SPAN&gt;VSS&lt;SPAN&gt;" so they are&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;independent Core switches. They are doing the routing to the private WAN, and will be doing the routing to the Edge Firewalls.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ECMP requires a dynamic routing protocol which usually you wouldn't&amp;nbsp;run on an edge firewall, you would just have the core set to default static route to the firewall. That being said not having a Stacked Core to operate as one, I would need each core switch connected to each firewall, so the paths are crossed. If I connect one core switch to one firewall and the other switch to the other firewall then a failure of the primary's firewall connected Core will fail the whole firewall pair over when they really didn't&amp;nbsp;need to be. So I am interested in how others are designing their edge firewalls to the Internet?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thoughts? Ideas? Caveats?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Dec 2017 15:56:47 GMT</pubDate>
    <dc:creator>s.williams1</dc:creator>
    <dc:date>2017-12-27T15:56:47Z</dc:date>
    <item>
      <title>Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193176#M57941</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I am trying to design the edge firewall and core network currently and I have a core Layer not in a "stack" or "&lt;/SPAN&gt;VSS&lt;SPAN&gt;" so they are&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;independent Core switches. They are doing the routing to the private WAN, and will be doing the routing to the Edge Firewalls.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ECMP requires a dynamic routing protocol which usually you wouldn't&amp;nbsp;run on an edge firewall, you would just have the core set to default static route to the firewall. That being said not having a Stacked Core to operate as one, I would need each core switch connected to each firewall, so the paths are crossed. If I connect one core switch to one firewall and the other switch to the other firewall then a failure of the primary's firewall connected Core will fail the whole firewall pair over when they really didn't&amp;nbsp;need to be. So I am interested in how others are designing their edge firewalls to the Internet?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thoughts? Ideas? Caveats?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 15:56:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193176#M57941</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-12-27T15:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193303#M57954</link>
      <description>&lt;P&gt;First off, ECMP does not &lt;EM&gt;require&lt;/EM&gt; a dynamic routing protocol. You can do ECMP with static routes if you want (not that I'm recommending this, but it's an option).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, there is absolutely no reason you couldn't run an IGP between your firewall cluster and L3 switches. This is perfectly fine, and common in larger networks. If your switches are not stacked, this is your best option (if anything, I would personally avoid stacking core switches).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Third, depending on your firewall model, ECMP may not get you any benefit. If your firewall can only process 1Gb/s for example, there's little benefit in having two ECMP 1Gb/s downlinks.&amp;nbsp;All you really care about in that scenario is redundancy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 14:46:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193303#M57954</guid>
      <dc:creator>9t89m8fu</dc:creator>
      <dc:date>2017-12-28T14:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193305#M57955</link>
      <description>&lt;P&gt;Yes I am not stacking core switches. Not even VSS. I rather let routing handle the failover. We have 3050s.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Datacenter_Redesign_concepts.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13106i5A4D1DC0D759519C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Datacenter_Redesign_concepts.jpg" alt="Datacenter_Redesign_concepts.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 3650s would be running HSRP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 14:50:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193305#M57955</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-12-28T14:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193370#M57975</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I take it that the PAN's would be Active/Active? Also is there a reason for the external switches and additional firewalls upstream? I try to follow the KISS principle and I try to make my PAN's the edge with the ISP upstream. I found that additional complexity upstream didnt help things, just made them worse.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my two cents.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 22:38:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193370#M57975</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-12-28T22:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193412#M57989</link>
      <description>&lt;P&gt;PAs would be active/standby. I would never make my firewalls my edge, it limits my ability to traffic engineer my BGP traffic. I would never want my firewalls taking on public BGP route tables.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 16:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193412#M57989</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-12-29T16:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193413#M57990</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In light of that informtaion, I think your desgin looks OK. I always like to add device priority ina ddition to link and path monitoring.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 16:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193413#M57990</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-12-29T16:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193667#M58032</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great conversation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm curious why you're going A/P over A/A, since&amp;nbsp; there does appear to be a chance for asyncronous routing(if that makes sense).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where I am, there are two Palos in AA, even though there's a singular internet connection(I didn't design it). However, I am responsible for rebuiliding things in a way similar to yours(except, it's been decided that VSS will run on the cores)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 19:23:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193667#M58032</guid>
      <dc:creator>DamianCleveland</dc:creator>
      <dc:date>2018-01-03T19:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193692#M58042</link>
      <description>&lt;P&gt;I would never run VSS on the core. I keep them separate and let routing take care of the fail-over as well as leveraging ECMP where I can. VSS is a pain to upgrade and have had more outages doing upgrades on a VSS pair then separate units.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;SPAN&gt;asyncronous routing should be fine because the switches between the edge firewalls and the edge routers will be running HSRP so only one will be actively forwarding traffic.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 19:52:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193692#M58042</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2018-01-03T19:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193694#M58044</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;As for the A/P vs A/A discussion, I see quite a lot of 'fixes' for A/A then A/P. Also in the past I have had many people ask me, why do you want that extra headache. I undertstand the need for A/A but I have worked in fairly large environments and a failover was never noticed. Granted we were not running voice or video over the PAN's :).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 20:06:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193694#M58044</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-03T20:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193701#M58045</link>
      <description>&lt;P&gt;I agree, the extra headache is not worth it. Just like my ASA days I tried to avoid multi-context Active/Active firewalls like the plague.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 20:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193701#M58045</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2018-01-03T20:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193704#M58047</link>
      <description>&lt;P&gt;I do the same with ASA's ;), aovoid them if I can. As for another A/P good thing. I used to upgrade a pair of 2050's years ago and I would VPN in with GP, upgrade the passive, reboot it, fail over, then upgrade and reboot the new passive without getting dropped from GP VPN.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 20:11:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193704#M58047</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-03T20:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Edge Firewall Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193706#M58048</link>
      <description>&lt;P&gt;Yes! Remote access for administration is criticial. I have a back door though on a cable modem connected to a PA500 for my "OOPS" moments.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 20:14:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edge-firewall-design/m-p/193706#M58048</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2018-01-03T20:14:00Z</dc:date>
    </item>
  </channel>
</rss>

