<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC VPN Tunnel Failover and Nexus 7K VPC Design in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193846#M58073</link>
    <description>&lt;P&gt;One thing I would like to point out is that I have only 1 link from each PAN to its corresponding Nexus so its not a criss-cross pattern. I'n not usre how you have yours wired up, but think that even in a X pattern it should work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What didnt seem to work during a failover?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jan 2018 14:57:59 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-01-04T14:57:59Z</dc:date>
    <item>
      <title>IPSEC VPN Tunnel Failover and Nexus 7K VPC Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193690#M58041</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A and B question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A. We have two Palos in A/S. The active has a functioning IPSEC VPN tunnel&amp;nbsp; terminated to it. Is there any way to have the tunnel renegotiate to the S when it becomes A?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;B. What is the proper way to design an A/S PA/Nexus 7k VPC environment, to best utilize the advantages of VPC technology?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 19:49:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193690#M58041</guid>
      <dc:creator>DamianCleveland</dc:creator>
      <dc:date>2018-01-03T19:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Tunnel Failover and Nexus 7K VPC Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193702#M58046</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a very similar setup except for 9K's. For question A the answer is, its automatic. The tunnel repoints to the active pan since it takes over everything. As for B, it might depend on you config. However what I have is trunks from the Nexus to the PAN and in some cases the vlan IP resides on the PAN and some on the Nexus (we are slowly migrating everything to the PAN).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps clear a few things up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 20:09:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193702#M58046</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-03T20:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Tunnel Failover and Nexus 7K VPC Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193708#M58049</link>
      <description>&lt;P&gt;Here is a basic stick drawing:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 646px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13119i628731E84978352B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 20:15:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193708#M58049</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-03T20:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Tunnel Failover and Nexus 7K VPC Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193828#M58070</link>
      <description>&lt;P&gt;Thanks for responding.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's good to hear that this works. When I tried, it didn't. I obviously did something wrong. Do have any documentation on this, by chance?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also appreciate the Nexus info. I'll double back, based on your recommedation, and try to get that connection going!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 12:51:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193828#M58070</guid>
      <dc:creator>DamianCleveland</dc:creator>
      <dc:date>2018-01-04T12:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Tunnel Failover and Nexus 7K VPC Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193846#M58073</link>
      <description>&lt;P&gt;One thing I would like to point out is that I have only 1 link from each PAN to its corresponding Nexus so its not a criss-cross pattern. I'n not usre how you have yours wired up, but think that even in a X pattern it should work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What didnt seem to work during a failover?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 14:57:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/193846#M58073</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-04T14:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Tunnel Failover and Nexus 7K VPC Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/194004#M58091</link>
      <description>&lt;P&gt;Otakar,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the imput.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My physical topology is the same as yours - no criss-cross pattern. One key difference is that we are using L3 point-to-point links instead of trunks and SVIs. Again, I'll have another look at things from the design perspective.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we failed-over the secondary device the tunnel did not, even though the standby-device reported that it was active. Granted, it was early in the implementation stage, then it was necessary to move on to other line items. Now it's time to revisit this, so I was curious if this actually worked. Since you say that it does, I'll take a more meticulous look at the design guides for the proper configuration to complete the task.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 14:53:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-failover-and-nexus-7k-vpc-design/m-p/194004#M58091</guid>
      <dc:creator>DamianCleveland</dc:creator>
      <dc:date>2018-01-05T14:53:47Z</dc:date>
    </item>
  </channel>
</rss>

