<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Acitve  Passive with different  Uplink IP address. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256454#M72756</link>
    <description>&lt;P&gt;anyone can tell me if this is possible to accomplish?&lt;/P&gt;</description>
    <pubDate>Sat, 06 Apr 2019 21:46:48 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-04-06T21:46:48Z</dc:date>
    <item>
      <title>Acitve  Passive with different  Uplink IP address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/254918#M72352</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two firerwalls at different locations conencted to different vendors via different ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I it possible to have uplink to vendor with same ISP but different IP address in active and passive setup?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 17:10:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/254918#M72352</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-25T17:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Acitve  Passive with different  Uplink IP address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/254967#M72363</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes this is possible, however remember that the passive device is (not active) so both ISP's will need to plug into both PAN's. Routing can be acheived via PBF or static routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 21:24:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/254967#M72363</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-25T21:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Acitve  Passive with different  Uplink IP address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/254969#M72364</link>
      <description>&lt;P&gt;As PA share the ip addresses in HA but with&amp;nbsp; with different uplink&amp;nbsp; on passive PA&amp;nbsp; how will failover&amp;nbsp; work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 21:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/254969#M72364</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-25T21:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Acitve  Passive with different  Uplink IP address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256454#M72756</link>
      <description>&lt;P&gt;anyone can tell me if this is possible to accomplish?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 21:46:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256454#M72756</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-04-06T21:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Acitve  Passive with different  Uplink IP address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256455#M72757</link>
      <description>&lt;P&gt;Are the firewalls managed by panorama?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 21:52:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256455#M72757</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-06T21:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Acitve  Passive with different  Uplink IP address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256462#M72758</link>
      <description>&lt;P&gt;yes they are&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 22:16:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256462#M72758</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-04-06T22:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Acitve  Passive with different  Uplink IP address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256465#M72761</link>
      <description>&lt;P&gt;I haven't try this so far, but technically it should be possible ... also with some limitations probably.&lt;/P&gt;&lt;P&gt;With panorama you are able to configure the devices of this a/p cluster independently (use template variables to be able to still configure as much as possible only once). Even if you configure different networks/interfaces for the two devices you can configure the same policy in one device group. Depending on the actual network configuration you can even use one NAT rule for the internet access. Here is also a limitation I can imagine: I don't know if the session sync properly works in an a/p cluster when there are different hide NAT addresses.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 22:24:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256465#M72761</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-06T22:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Acitve  Passive with different  Uplink IP address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256588#M72803</link>
      <description>&lt;P&gt;The best way to do this is to place your ISP connections outside of your FW environment&amp;nbsp;into a L2 Switch above.&amp;nbsp; Then connect your FWs into that switch.&amp;nbsp; You can utilize VLANs to make connectivity more seamless.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 13:52:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256588#M72803</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-04-08T13:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Acitve  Passive with different  Uplink IP address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256629#M72824</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;The best way to do this is to place your ISP connections outside of your FW environment&amp;nbsp;into a L2 Switch above.&amp;nbsp; Then connect your FWs into that switch.&amp;nbsp; You can utilize VLANs to make connectivity more seamless.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The description of &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;sounds like there is no possibility of spanning the L2 VLANs across the locations. But if there is the possibility for that then &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;you should definately consider the input of &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 17:13:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256629#M72824</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-08T17:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Acitve  Passive with different  Uplink IP address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256643#M72826</link>
      <description>&lt;P&gt;Another option -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could simply run them independently and have them both advertise the default route into whatever dynamic routing protocol you are using.&amp;nbsp; Site-A would prefer FW-A (closest to it) and Site-B would prefer FW-B (closest to it).&amp;nbsp; This would cause sessions to have to be reinitialized in the event that one of the FW goes down for whatever reason.&amp;nbsp;If you are providing any inbound services, you would need something like an F5 and GSLB to use DNS to move traffic away from a downed FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sounds like L2 connectivity between sites is a no go?&amp;nbsp; If not, you could also consider Active/Active which would handle asynchronous routing and allow for both ISPs to be utilized like above, but with state mantained.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 19:15:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acitve-passive-with-different-uplink-ip-address/m-p/256643#M72826</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-04-08T19:15:18Z</dc:date>
    </item>
  </channel>
</rss>

