<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Virtual IP address in HA- Active Passive Mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-ip-address-in-ha-active-passive-mode/m-p/224117#M64385</link>
    <description>&lt;P&gt;I forget the name of the option, but in the High Availability&amp;nbsp;settings is a fast switchover option that can be enabled.&lt;BR /&gt;&lt;BR /&gt;The default has the interfaces on the passive firewall marked&amp;nbsp;as "down" so there's no link with the switch. When a fail-over occurs, the interfaces are&amp;nbsp;marked as "up", they negotiate a link with the switch, then do all the ARP stuff. There's about a 2 second pause in traffic while this happens.&lt;BR /&gt;&lt;BR /&gt;With the fast switchover enabled, the interfaces on the passive device are "up", there's a link with the switch, but the firewall drops all traffic on those ports. When a fail-over occurs, it just does the ARP stuff and there's only a 200-400 ms blip where only a few individual packets should be lost (if even that many).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&amp;nbsp; fixed spelling and typos due to using a phone for the original post.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Aug 2018 19:59:36 GMT</pubDate>
    <dc:creator>fjwcash</dc:creator>
    <dc:date>2018-08-10T19:59:36Z</dc:date>
    <item>
      <title>Virtual IP address in HA- Active Passive Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-ip-address-in-ha-active-passive-mode/m-p/224094#M64384</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've query about High Availability Active-Passive. As we know, interface IP addresses are same on both the firewalls and when Active device goes down, secondary firewall will take over by sending gratuitous arp to switches. So switches can learn about the new Mac addresses and traffic start forwarding. But this causes a blip in network traffic forwarding .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way we can configure&amp;nbsp; floating IP address/ Virtual IP address for each interfaces in Active-Passive mode like HSRP , so traffic can be forwarded without any interruption or this is supported only in Active-Active mode. Please assist.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 22:42:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-ip-address-in-ha-active-passive-mode/m-p/224094#M64384</guid>
      <dc:creator>nsrini1991</dc:creator>
      <dc:date>2018-07-30T22:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual IP address in HA- Active Passive Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-ip-address-in-ha-active-passive-mode/m-p/224117#M64385</link>
      <description>&lt;P&gt;I forget the name of the option, but in the High Availability&amp;nbsp;settings is a fast switchover option that can be enabled.&lt;BR /&gt;&lt;BR /&gt;The default has the interfaces on the passive firewall marked&amp;nbsp;as "down" so there's no link with the switch. When a fail-over occurs, the interfaces are&amp;nbsp;marked as "up", they negotiate a link with the switch, then do all the ARP stuff. There's about a 2 second pause in traffic while this happens.&lt;BR /&gt;&lt;BR /&gt;With the fast switchover enabled, the interfaces on the passive device are "up", there's a link with the switch, but the firewall drops all traffic on those ports. When a fail-over occurs, it just does the ARP stuff and there's only a 200-400 ms blip where only a few individual packets should be lost (if even that many).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&amp;nbsp; fixed spelling and typos due to using a phone for the original post.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 19:59:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-ip-address-in-ha-active-passive-mode/m-p/224117#M64385</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-08-10T19:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual IP address in HA- Active Passive Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-ip-address-in-ha-active-passive-mode/m-p/224161#M64392</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42838"&gt;@fjwcash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;On the HA settings under 'Active/Passive Settings' you can set the 'Passive Link State' to either Shutdown or Auto. By default this will be set to "Shutdown", in this state upstream and downstream devices will not see a valid path until the passive becomes active.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Auto will bring the interfaces on the firewall into a 'link up' state, but blocks all inbound and outbound traffic to the interfaces until the firewall becomes active. This eliminates a lot of the the failover time. The device in passive sate will not forward traffic or respond to ARP requests until the device is active.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Either option is pretty save regardless of which one you select, but there are a few things to keep in mind when setting things to Auto. Layer 3 depoloyments you obviously have the advantage of GARPs (2 immediately then 8*1sec) that will update the MAC tables.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Layer2 deplolyments you need to keep RSTP in mind. You'll want to enable RSTP on all switch interfaces that connect to the firewall (layer2 interfaces) to prevent any loops between the firewall HA members.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 14:07:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-ip-address-in-ha-active-passive-mode/m-p/224161#M64392</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-31T14:07:07Z</dc:date>
    </item>
  </channel>
</rss>

