<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active/Standby network design and usage as network gateway? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-standby-network-design-and-usage-as-network-gateway/m-p/241504#M69155</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So yes to the first paragraph. And yes to keeping the interfaces in a shutdown state on the standby unit. I run A/S and dont have issues, I also run OSPF and it doesnt really mind much since the S has the sessions in it. I think last time I failed them over I maybe lost 1-2 pings. This is usually quick enough for dynamic routing since the timers are usually longer than that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for using the PAN as a L3 Vlan interface, I also do this since I can then segregate the traffic and get closer to a Zero Trust model. One thing I do is have one zone and carve it up into smaller subnets so that I dont run out of zones.&lt;/P&gt;&lt;P&gt;i.e.&amp;nbsp;&lt;/P&gt;&lt;P&gt;zone ZeroTrust&lt;/P&gt;&lt;P&gt;IP subnets 192.168.0.0/24 then carve them up into /29's. Since I have a DENY ALL policy, the intra zone traffic doesnt take affect and the traffic has to be allowed between two subnets in the same zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Nov 2018 20:51:00 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-11-28T20:51:00Z</dc:date>
    <item>
      <title>Active/Standby network design and usage as network gateway?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-standby-network-design-and-usage-as-network-gateway/m-p/241498#M69154</link>
      <description>&lt;P&gt;I have some questions on the Active/Standby deployment model.&amp;nbsp; Right now I'm on A/A which requires all network config between the two units to be different since they're both active at the same time.&amp;nbsp; From looking at the documentation, it looks like in an A/S model the network config between the two units is identical which includes all of the same IP addresses on subinterfaces, virtual routers, etc.&amp;nbsp; Is this correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If so, does the standby simply keep its interfaces shut while not active?&amp;nbsp; During a failover scenario, does the switchover happen fast enough that dynamic routing protocols to not notice and therefore not require reconvergence?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm aslo wondering if anyone uses their firewalls for the L3 network gateways for any of their VLANs?&amp;nbsp; I was considering setting up subinterfaces and maybe using them for our DC networks so that the firewall could more directly dictate for each server what it can and not have access to without doing ACLs on a Cisco switch or router.&amp;nbsp; Alternatively, I'd probably use Policy Based Routing to push the traffic from the network's gateway to the firewall.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 20:41:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-standby-network-design-and-usage-as-network-gateway/m-p/241498#M69154</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2018-11-28T20:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Standby network design and usage as network gateway?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-standby-network-design-and-usage-as-network-gateway/m-p/241504#M69155</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So yes to the first paragraph. And yes to keeping the interfaces in a shutdown state on the standby unit. I run A/S and dont have issues, I also run OSPF and it doesnt really mind much since the S has the sessions in it. I think last time I failed them over I maybe lost 1-2 pings. This is usually quick enough for dynamic routing since the timers are usually longer than that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for using the PAN as a L3 Vlan interface, I also do this since I can then segregate the traffic and get closer to a Zero Trust model. One thing I do is have one zone and carve it up into smaller subnets so that I dont run out of zones.&lt;/P&gt;&lt;P&gt;i.e.&amp;nbsp;&lt;/P&gt;&lt;P&gt;zone ZeroTrust&lt;/P&gt;&lt;P&gt;IP subnets 192.168.0.0/24 then carve them up into /29's. Since I have a DENY ALL policy, the intra zone traffic doesnt take affect and the traffic has to be allowed between two subnets in the same zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 20:51:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-standby-network-design-and-usage-as-network-gateway/m-p/241504#M69155</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-11-28T20:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Standby network design and usage as network gateway?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-standby-network-design-and-usage-as-network-gateway/m-p/241507#M69157</link>
      <description>&lt;P&gt;I use auto not shutdown.&lt;/P&gt;&lt;P&gt;In this case port is active it just drops any incoming packets.&lt;/P&gt;&lt;P&gt;Benefit is faster failover.&lt;/P&gt;&lt;P&gt;&lt;A title="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcACAS" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcACAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcACAS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 21:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-standby-network-design-and-usage-as-network-gateway/m-p/241507#M69157</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-28T21:04:05Z</dc:date>
    </item>
  </channel>
</rss>

