<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Moving a Layer Two Switch between FW pair and Edge Router from ISP Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/moving-a-layer-two-switch-between-fw-pair-and-edge-router-from/m-p/218146#M63064</link>
    <description>&lt;P&gt;We are attempting to move a pair of VCP'd layer 2 switches between our ISP's CIENA and our PA 5220 pair.&amp;nbsp; Our ISP is only giving us a single handoff so we were attempting to plug the handoff into the layer 2 switches (nexus 9ks with VCP) on a access port with vlan 602.&amp;nbsp; The switches also have trunk ports connecting to the Palo Alto's with LACP.&lt;BR /&gt;&lt;BR /&gt;We were able to see arp entries for the Palo Alto and the Ciena from the Nexus and could ping the Ciena BGP peer address from the palo alto.&amp;nbsp; Unfortunately the BGP session would only say connected and never established. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The ISP was unhelpful and said that in their experience that type of setup doesn't work and that in the rare cases it does you have to do configuration on your side.&amp;nbsp; (Suprise suprise!).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any thoughts?&amp;nbsp; We tried raising hop count dramatically, resetting ISP router in case it was an arp caching issue on their side, etc.&lt;/P&gt;</description>
    <pubDate>Sun, 17 Jun 2018 08:22:15 GMT</pubDate>
    <dc:creator>davic09</dc:creator>
    <dc:date>2018-06-17T08:22:15Z</dc:date>
    <item>
      <title>Moving a Layer Two Switch between FW pair and Edge Router from ISP Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-a-layer-two-switch-between-fw-pair-and-edge-router-from/m-p/218146#M63064</link>
      <description>&lt;P&gt;We are attempting to move a pair of VCP'd layer 2 switches between our ISP's CIENA and our PA 5220 pair.&amp;nbsp; Our ISP is only giving us a single handoff so we were attempting to plug the handoff into the layer 2 switches (nexus 9ks with VCP) on a access port with vlan 602.&amp;nbsp; The switches also have trunk ports connecting to the Palo Alto's with LACP.&lt;BR /&gt;&lt;BR /&gt;We were able to see arp entries for the Palo Alto and the Ciena from the Nexus and could ping the Ciena BGP peer address from the palo alto.&amp;nbsp; Unfortunately the BGP session would only say connected and never established. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The ISP was unhelpful and said that in their experience that type of setup doesn't work and that in the rare cases it does you have to do configuration on your side.&amp;nbsp; (Suprise suprise!).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any thoughts?&amp;nbsp; We tried raising hop count dramatically, resetting ISP router in case it was an arp caching issue on their side, etc.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jun 2018 08:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-a-layer-two-switch-between-fw-pair-and-edge-router-from/m-p/218146#M63064</guid>
      <dc:creator>davic09</dc:creator>
      <dc:date>2018-06-17T08:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Moving a Layer Two Switch between FW pair and Edge Router from ISP Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-a-layer-two-switch-between-fw-pair-and-edge-router-from/m-p/218155#M63067</link>
      <description>&lt;P&gt;I assume the ISP is not able to give you dual handoff in the same layer 2 domain.&amp;nbsp; This is our first approach to this type of request as an ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also assume that the PA cluster is active/passive with a single peering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the peering work when directly connected to one PAN or was that not attempted?&lt;/P&gt;&lt;P&gt;This would be good information to have even if it cannot stay that way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is not clear if this is a peer direct or multihop without the move.&amp;nbsp; I would assume this is a direct link peer.&amp;nbsp; If so, setting multihop won't make any difference and that parameter does need to match on both peers if it is multihop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running a pcap during the failure should give more detailed information on the issue the instructions are here.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Open-a-Support-Case-on-Routing-Issues-OSPF-and-BGP/ta-p/132153" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Open-a-Support-Case-on-Routing-Issues-OSPF-and-BGP/ta-p/132153&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jun 2018 12:21:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-a-layer-two-switch-between-fw-pair-and-edge-router-from/m-p/218155#M63067</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-06-17T12:21:29Z</dc:date>
    </item>
  </channel>
</rss>

