<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA for interface pair as a DHCP client in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-for-interface-pair-as-a-dhcp-client/m-p/240244#M68857</link>
    <description>&lt;P&gt;When you add firewalls to HA then mac address is generated based on group id in HA settings.&lt;/P&gt;&lt;P&gt;So both IP and mac are moved over between firewalls in HA.&lt;/P&gt;</description>
    <pubDate>Sat, 17 Nov 2018 23:18:58 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2018-11-17T23:18:58Z</dc:date>
    <item>
      <title>HA for interface pair as a DHCP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-for-interface-pair-as-a-dhcp-client/m-p/240237#M68856</link>
      <description>&lt;P&gt;I have a pair of VM-50 as an HA pair. When the primary firewall fails the IP is moved to the new active node but the MAC address changes and the ISP cable modem most likely does not accept this. The only resolution is to release and renew the DHCP address which is obvisouly not a workable solution for an automatic failover.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Nov 2018 22:59:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-for-interface-pair-as-a-dhcp-client/m-p/240237#M68856</guid>
      <dc:creator>aarato</dc:creator>
      <dc:date>2018-11-17T22:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: HA for interface pair as a DHCP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-for-interface-pair-as-a-dhcp-client/m-p/240244#M68857</link>
      <description>&lt;P&gt;When you add firewalls to HA then mac address is generated based on group id in HA settings.&lt;/P&gt;&lt;P&gt;So both IP and mac are moved over between firewalls in HA.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Nov 2018 23:18:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-for-interface-pair-as-a-dhcp-client/m-p/240244#M68857</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-17T23:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: HA for interface pair as a DHCP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-for-interface-pair-as-a-dhcp-client/m-p/240245#M68858</link>
      <description>&lt;P&gt;Thanks for the response. The Mac Address is not migrating over when there is a failover. See below. This is in an ESXi environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name: ethernet1/1, ID: 16&lt;BR /&gt;Link status:&lt;BR /&gt;Runtime link speed/duplex/state: 10000/full/up&lt;BR /&gt;Configured link speed/duplex/state: auto/auto/auto&lt;BR /&gt;MAC address:&lt;BR /&gt;Port MAC address 00:0c:29:34:b8:61 &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;nbsp;Before failover&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Untagged sub-interface support: no&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ethernet1/1, ID: 16&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Virtual router DEFVRF&lt;BR /&gt;Interface MTU 1500&lt;BR /&gt;Interface IP address (dynamic): XX.YY.175.22/32&lt;/P&gt;&lt;P&gt;admin@PA1(active)&amp;gt; request high-availability state suspend&lt;/P&gt;&lt;P&gt;Successfully changed HA state to suspended&lt;BR /&gt;admin@PA1(suspended)&amp;gt;&lt;/P&gt;&lt;P&gt;admin@PA1(suspended)&amp;gt; show interface ethernet1/1&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ethernet1/1, ID: 16&lt;BR /&gt;Link status:&lt;BR /&gt;Runtime link speed/duplex/state: unknown/unknown/down&lt;BR /&gt;Configured link speed/duplex/state: auto/auto/auto&lt;BR /&gt;MAC address:&lt;BR /&gt;Port MAC address 00:0c:29:34:b8:61&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Untagged sub-interface support: no&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ethernet1/1, ID: 16&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Virtual router DEFVRF&lt;BR /&gt;Interface MTU 1500&lt;BR /&gt;Interface IP address (dynamic): XX.YY.175.22/32&amp;nbsp;&lt;SPAN&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;nbsp;After failover&lt;/SPAN&gt;&lt;BR /&gt;Interface management profile: PING&lt;BR /&gt;ping: yes telnet: no ssh: no http: no https: no&lt;BR /&gt;snmp: no response-pages: no userid-service: no&lt;BR /&gt;Service configured:&lt;BR /&gt;Zone: Untrust, virtual system: vsys1&lt;BR /&gt;Adjust TCP MSS: no&lt;BR /&gt;Policing: no&lt;BR /&gt;admin@PA1(suspended)&amp;gt; request high-availability state functional&lt;/P&gt;&lt;P&gt;Successfully changed HA state to functional&lt;BR /&gt;admin@PA1(initial)&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the other vm which become ative with its own vmware MAC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-VM(active)&amp;gt; show interface ethernet1/1&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ethernet1/1, ID: 16&lt;BR /&gt;Link status:&lt;BR /&gt;Runtime link speed/duplex/state: unknown/unknown/down&lt;BR /&gt;Configured link speed/duplex/state: auto/auto/auto&lt;BR /&gt;MAC address:&lt;BR /&gt;Port MAC address 00:50:56:92:19:11 &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; OTHER SIDE MAC&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Untagged sub-interface support: no&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ethernet1/1, ID: 16&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Virtual router DEFVRF&lt;BR /&gt;Interface MTU 1500&lt;BR /&gt;Interface IP address (dynamic): XX.YY.175.22/32&amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; OTHER side Has the same IP&lt;BR /&gt;Interface management profile: PING&lt;BR /&gt;ping: yes telnet: no ssh: no http: no https: no&lt;BR /&gt;snmp: no response-pages: no userid-service: no&lt;BR /&gt;Service configured:&lt;BR /&gt;Zone: Untrust, virtual system: vsys1&lt;BR /&gt;Adjust TCP MSS: no&lt;BR /&gt;Policing: no&lt;BR /&gt;admin@PA-VM(active)&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Nov 2018 04:21:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-for-interface-pair-as-a-dhcp-client/m-p/240245#M68858</guid>
      <dc:creator>aarato</dc:creator>
      <dc:date>2018-11-18T04:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: HA for interface pair as a DHCP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-for-interface-pair-as-a-dhcp-client/m-p/240246#M68859</link>
      <description>&lt;P&gt;One option would be to disable "Use Hypervisor Assigned MAC Address".&lt;/P&gt;&lt;P&gt;After that try if you can manually assign same HA generated mac address that floats then between firewalls to both virtual machine nic cards in VMware or other option is to turn WAN virtual switch into promiscuos mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue with promiscuos mode is that switch starts acting as hub and every vnic connected to that virtual switch will receive every single packet.&lt;/P&gt;&lt;P&gt;Would not be an problem if you only have ISP and 2 Palo WAN interfaces there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.paloaltonetworks.com/documentation/80/virtualization/virtualization/about-the-vm-series-firewall/hypervisor-assigned-mac-addresses" href="https://www.paloaltonetworks.com/documentation/80/virtualization/virtualization/about-the-vm-series-firewall/hypervisor-assigned-mac-addresses" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/virtualization/virtualization/about-the-vm-series-firewall/hypervisor-assigned-mac-addresses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Nov 2018 05:05:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-for-interface-pair-as-a-dhcp-client/m-p/240246#M68859</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-18T05:05:40Z</dc:date>
    </item>
  </channel>
</rss>

