<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-820 &amp;amp; LACP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-820-amp-lacp/m-p/288216#M76817</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36075"&gt;@ShaiW&lt;/a&gt;&amp;nbsp;There is an option to configure passive HA firewall interfaces in state "Auto" and enable LACP, however this is only supported on the 3 and 5 series and not on the 820. See article below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/ha-concepts/lacp-and-lldp-pre-negotiation-for-activepassive-ha" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/ha-concepts/lacp-and-lldp-pre-negotiation-for-activepassive-ha&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;your only option is to configure passive interfaces to "shutdown", so at least you will not get LACP errorrs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Sep 2019 07:34:39 GMT</pubDate>
    <dc:creator>BatD</dc:creator>
    <dc:date>2019-09-13T07:34:39Z</dc:date>
    <item>
      <title>PA-820 &amp; LACP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-820-amp-lacp/m-p/288074#M76791</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Just wondering if anyone here has successfully gotten LACP to work on a PA-800 series FW (set to passive) and Cisco Switch (set as 'channel-group X mode active')?&lt;/P&gt;&lt;P&gt;No matter what I try (fast/slow/active/passive/1 eth/2 eth) I always get "&lt;SPAN class="st"&gt;&lt;EM&gt;LACP&lt;/EM&gt; currently &lt;EM&gt;not enabled&lt;/EM&gt; on the &lt;EM&gt;remote port&lt;/EM&gt;&lt;/SPAN&gt;" in the Cisco console output.&lt;/P&gt;&lt;P&gt;I saw this twice this week at two different deplyments - don't know what switch is used on the second deployment, but LACP fails to work regardless).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a special configuration on the Cisco side that we might have missed? Maybe due to PA-800 not supporting pre-negotiation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Shai&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 11:16:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-820-amp-lacp/m-p/288074#M76791</guid>
      <dc:creator>ShaiW</dc:creator>
      <dc:date>2019-09-12T11:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: PA-820 &amp; LACP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-820-amp-lacp/m-p/288128#M76797</link>
      <description>&lt;P&gt;Howdy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not think it is a misconfiguration on either product. I think it understanding how the PANW firewall does passive firewall interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By default, in HA on the PANW firewalls, the EXACT configuration (minus HA and Admin accounts) is synch'd across both FWs.&lt;/P&gt;&lt;P&gt;Because both Active and Passive FW have the EXACT inside IP/mask, there needed to be a way to ensure the passive fw did NOT try to respond to arp requests, when it was in passive mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is accomplished (and I think this the issue), by ensuring that the passive fw interfaces are administratively DOWN.&lt;/P&gt;&lt;P&gt;This seems to be the reason why you would not get LACP adjancency.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you change the setting to up, it may assist in adjacency for LACP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-09-12 12_56_06-.png" style="width: 531px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21355i2ACF4354F5C1D91E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-09-12 12_56_06-.png" alt="2019-09-12 12_56_06-.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 16:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-820-amp-lacp/m-p/288128#M76797</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-09-12T16:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: PA-820 &amp; LACP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-820-amp-lacp/m-p/288216#M76817</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36075"&gt;@ShaiW&lt;/a&gt;&amp;nbsp;There is an option to configure passive HA firewall interfaces in state "Auto" and enable LACP, however this is only supported on the 3 and 5 series and not on the 820. See article below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/ha-concepts/lacp-and-lldp-pre-negotiation-for-activepassive-ha" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/ha-concepts/lacp-and-lldp-pre-negotiation-for-activepassive-ha&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;your only option is to configure passive interfaces to "shutdown", so at least you will not get LACP errorrs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 07:34:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-820-amp-lacp/m-p/288216#M76817</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-09-13T07:34:39Z</dc:date>
    </item>
  </channel>
</rss>

