<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Redundant Interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/219033#M63277</link>
    <description>&lt;P&gt;Agree that is ugly and non-standard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bear in mind that when you leave the company when your replacement sees this they will curse your name forever.&amp;nbsp; Assuming they can even figure out why it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Jun 2018 11:19:09 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2018-06-24T11:19:09Z</dc:date>
    <item>
      <title>Redundant Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/218777#M63224</link>
      <description>&lt;P&gt;Is there a good way to make an AE act like an ASA redundant interface? Basically all traffic goes through one interface unless it fails, then goes to the other interface.&lt;/P&gt;&lt;P&gt;I'm looking for the same functionality that the ASA redundant interface provides but don't see a good way to do it.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 23:00:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/218777#M63224</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-06-21T23:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Redundant Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/218850#M63236</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could achieve this via a Policy Based Forwarding rule. Configure traffic to go down your main interface, with the PBF rule monitoring the gateway/next hop of that interface then use the option "disable this rule if nexthop/monitor IP is not available". Then have another PBF rule underneath that sends traffic out the redundant interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 13:27:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/218850#M63236</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-22T13:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Redundant Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/218961#M63262</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;An ae interface is just lacp, so its bundled so traffic flows via both unless it down. However PBF rules as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;mentioned should help with this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 17:53:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/218961#M63262</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-22T17:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Redundant Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/219014#M63273</link>
      <description>&lt;P&gt;The Cisco ASA is implementing the ethernet standard PRP for redundant ethernet connections.&amp;nbsp; This standard is not supported by PAN devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your next best option is to configure AE ports on both the PAN and switch which would be supported properly configured on both sides and would also survive the loss of one physical link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both of these are layer 2 redundancy protocols.&amp;nbsp; I would not recommend replacing a layer 2 redundancy with policy based routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jun 2018 16:18:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/219014#M63273</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-06-23T16:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Redundant Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/219016#M63275</link>
      <description>&lt;P&gt;If at all possible, I'd configure the AE with LACP.&amp;nbsp; That's the best option.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a way to get functionality similar to the ASA redundant interface, but it's ugly (unique, different, non-traditional, thinking outside the box, etc.)&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.) Instead of an AE configured as Layer-3 (or L3 with sub-interfaces), you would configure 2x Layer-2 interfaces on the firewall (with a vlan.x interface to handle Layer-3 duties).&lt;/P&gt;&lt;P&gt;2.) Configure your switch for spanning-tree (the firewall doesn't participate in the STP process, but it will pass the protocol between the L2 interfaces)&lt;/P&gt;&lt;P&gt;3.) Plug both firewall interfaces into your switch&lt;/P&gt;&lt;P&gt;4.) See switch determine that there would be a network loop if both interfaces would be active.&amp;nbsp; Switch will move one of the interfaces into a "blocking" status.&lt;/P&gt;&lt;P&gt;5.) Disconnect the active firewall interface from the switch&lt;/P&gt;&lt;P&gt;6.) See the switch react accordingly and bring up the "backup interface".&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because the firewall doesn't participate in the STP process, steps #4 and #6 will take ~30 seconds.&amp;nbsp; That's how long the switch will take to complete the STP process.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jun 2018 19:02:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/219016#M63275</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-06-23T19:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Redundant Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/219033#M63277</link>
      <description>&lt;P&gt;Agree that is ugly and non-standard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bear in mind that when you leave the company when your replacement sees this they will curse your name forever.&amp;nbsp; Assuming they can even figure out why it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jun 2018 11:19:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundant-interface/m-p/219033#M63277</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-06-24T11:19:09Z</dc:date>
    </item>
  </channel>
</rss>

