<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practice for HA1 IP address in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-ha1-ip-address/m-p/208460#M61020</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;. That said I always use RFC 1918 addresses for my HA IP's. This way they can never get routed externally even if the two devices have to be be routed if they are in different locations, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Mon, 02 Apr 2018 19:32:35 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-04-02T19:32:35Z</dc:date>
    <item>
      <title>Best Practice for HA1 IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-ha1-ip-address/m-p/208374#M60990</link>
      <description>&lt;P&gt;I have a lots of customers who uses HA pair with 1.1.1.1/30 and 1.1.1.2/30 for HA1 port.&lt;/P&gt;&lt;P&gt;This HA1 port connected directly. And reason for selecting these IPs are because nobody was using it in the past.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today, I read this article:&lt;/P&gt;&lt;P&gt;&lt;A href="https://blog.cloudflare.com/announcing-1111/" target="_blank"&gt;https://blog.cloudflare.com/announcing-1111/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theverge.com/2018/4/1/17185732/cloudflare-dns-service-1-1-1-1" target="_blank"&gt;https://www.theverge.com/2018/4/1/17185732/cloudflare-dns-service-1-1-1-1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to &lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Best-practice-for-assigning-IP-addresses-to-HA1-and-HA2-on/m-p/139727" target="_self"&gt;this thread&lt;/A&gt;, it sounds okay to keep using 1.1.1.1 for HA1, though I'm curious... do they need to change IPs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition, with my quick test in my lab, I can access to 1.1.1.1 DNS server even HA1 is using 1.1.1.1, thus I believe 1.1.1.1 for HA1 is okay.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Emr&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 07:52:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-ha1-ip-address/m-p/208374#M60990</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2018-04-02T07:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for HA1 IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-ha1-ip-address/m-p/208392#M60997</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3296"&gt;@emr_1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;HA links are usually directly connected and therefore the IP doesn't really matter since the traffic will never be routed.&lt;/P&gt;&lt;P&gt;APNIC releasing 1.1.1.1 to CloudFlare is one of the most unreasonable&amp;nbsp;things I've seen in a long time. APNIC has attempted to analyze how much traffic attempt to route to 1.1.1.1 multiple different times and have been unable; CloudFlare offering to do this for them in exchange of allowing them to utilize the IP is the only reason they were allocated the address.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 13:56:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-ha1-ip-address/m-p/208392#M60997</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-02T13:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for HA1 IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-ha1-ip-address/m-p/208460#M61020</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;. That said I always use RFC 1918 addresses for my HA IP's. This way they can never get routed externally even if the two devices have to be be routed if they are in different locations, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 19:32:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-ha1-ip-address/m-p/208460#M61020</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-04-02T19:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for HA1 IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-ha1-ip-address/m-p/208512#M61042</link>
      <description>&lt;P&gt;oh wow, this is a pretty important thing to consider when 'nonchalantly' using 1.1.1.1 instead of a proper RFC1918 or RFC5735 (documentation) IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;just thinking dns sinkhole,....&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 08:29:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-ha1-ip-address/m-p/208512#M61042</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-04-03T08:29:55Z</dc:date>
    </item>
  </channel>
</rss>

