<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA firewalls and HA across different GEO locations in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215289#M62479</link>
    <description>&lt;P&gt;It is not why i want . Client is asking if it is possible are not what it is the recommendation if we do ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second,&amp;nbsp;if so what is the recommendation they asking is it safe or not due to a different location?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does Palo Alto recommend&amp;nbsp;or not if do not what is the normal recommendation&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 May 2018 07:55:42 GMT</pubDate>
    <dc:creator>NavidAlam</dc:creator>
    <dc:date>2018-05-24T07:55:42Z</dc:date>
    <item>
      <title>PA firewalls and HA across different GEO locations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215163#M62461</link>
      <description>&lt;P&gt;Hi Support,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have Client in Cork want to know about the FW HA across Different Location.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What are requirements for having fw cluster spread across different GEO locations (latency, delay, etc)?&lt;/LI&gt;&lt;LI&gt;Is this recommended at all by PA? If yes, what kind of link is required for HA connectivity (L3, L2)?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have some ideas of spreading current firewall cluster between new Data Cente in Dublin and DR site different location.&lt;/P&gt;&lt;P&gt;Is it not good idea because of possible split brain scenarios due to periodical link latency.&lt;/P&gt;&lt;P&gt;Basically to take passive current FW appliance and rack it to different location &amp;nbsp;so that active/passive cluster is spread .&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2018 12:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215163#M62461</guid>
      <dc:creator>NavidAlam</dc:creator>
      <dc:date>2018-05-23T12:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: PA firewalls and HA across different GEO locations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215197#M62467</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76136"&gt;@NavidAlam&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can overcome any latency situation by adjusting the HA settings themselves, but I kind of have to ask&amp;nbsp;&lt;EM&gt;why&lt;/EM&gt; you would want to setup like this. Usually if you build out a different data center in a completely different location you utilize load-balancing or DNS changes to kick the traffic over when you need it. I've never seen anyone have such geographically diversified firewalls running in an active/passive pair; not because you can't do so, but why would you want to?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2018 15:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215197#M62467</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-23T15:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: PA firewalls and HA across different GEO locations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215289#M62479</link>
      <description>&lt;P&gt;It is not why i want . Client is asking if it is possible are not what it is the recommendation if we do ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second,&amp;nbsp;if so what is the recommendation they asking is it safe or not due to a different location?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does Palo Alto recommend&amp;nbsp;or not if do not what is the normal recommendation&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 07:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215289#M62479</guid>
      <dc:creator>NavidAlam</dc:creator>
      <dc:date>2018-05-24T07:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: PA firewalls and HA across different GEO locations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215429#M62494</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76136"&gt;@NavidAlam&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes it's possible, the recommendation would be to set the HA timers with the time consideration that it will take to travel whatever distance you are putting them across. This will depend on the link and how long it actually is. You'll need to set the HA Timers to 'Advanced' and actually manually set these in accordance with the latency on this link.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This type of setup&amp;nbsp;&lt;STRONG&gt;would not&lt;/STRONG&gt; be recommended. You're essentially asking to seperate an HA Active/Passive pair over 260km and expecting it to perform well.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 23:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215429#M62494</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-24T23:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: PA firewalls and HA across different GEO locations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215505#M62504</link>
      <description>&lt;P&gt;My DR site is 5 miles away over a 1Gb fibre link, would not consider HA on that. We can manage most of the inbound trafic changes easily, and outbound does not matter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 16:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/215505#M62504</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-05-25T16:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA firewalls and HA across different GEO locations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/558918#M113365</link>
      <description>&lt;P&gt;Hi, this is interesting question. If I setup timers on HA communication to huge delay the cluster PA will be works? Is exist any official document on site palo alto?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 05:58:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-and-ha-across-different-geo-locations/m-p/558918#M113365</guid>
      <dc:creator>AndrzejPiotrowski</dc:creator>
      <dc:date>2023-09-21T05:58:22Z</dc:date>
    </item>
  </channel>
</rss>

