<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Data Link Ethernet  vs IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290713#M77167</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56277"&gt;@junior_r&lt;/a&gt;&amp;nbsp; I have also seen it a lot and I think the only reason people are doing it is because of not knowing that IP is not required when the firewalls are directly connected.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Oct 2019 06:44:06 GMT</pubDate>
    <dc:creator>BatD</dc:creator>
    <dc:date>2019-10-01T06:44:06Z</dc:date>
    <item>
      <title>HA Data Link Ethernet  vs IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290445#M77122</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I configure HA for data link I use Ethernet when devices are directly connected to each other, but sometimes in the field I see people using IP for transport but the devices are directly connected to each other. Why are they doing this? There is no reason to do it unless it needs to route. Can someone help me understand there logic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 28 Sep 2019 17:19:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290445#M77122</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2019-09-28T17:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: HA Data Link Ethernet  vs IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290713#M77167</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56277"&gt;@junior_r&lt;/a&gt;&amp;nbsp; I have also seen it a lot and I think the only reason people are doing it is because of not knowing that IP is not required when the firewalls are directly connected.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 06:44:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290713#M77167</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-10-01T06:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: HA Data Link Ethernet  vs IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290722#M77169</link>
      <description>&lt;P&gt;I manage an HA active/standby pair of PA-5220, and we had to switch from ethernet to IP based HA because of AUX ports limitations and bug&amp;nbsp;PAN-105737 (*). We surely could have solved it with a minimal configuration, but we opted to fully configure all HA interfaces (i.e. ip, netmask and gateway). We must use AUX ports because we are about to split the couple in two different datacenters.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;(*) If you use the AUX 1 or AUX 2 interface and you do not configure an IP address, network mask, and default gateway for the interface, the interface will not come up when you upgrade the firewall to PAN-OS 8.1.7. The most common use of AUX interfaces is to configure AUX ports as HA1 and HA1 Backup interfaces for fiber connections on PA-5200 Series firewalls in an HA configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Workaround:&amp;nbsp;&lt;SPAN&gt;To avoid a split-brain scenario in HA configurations as a result of this issue, configure a default gateway on at least one of the AUX interfaces.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 01 Oct 2019 08:56:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290722#M77169</guid>
      <dc:creator>michelealbrigo</dc:creator>
      <dc:date>2019-10-01T08:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: HA Data Link Ethernet  vs IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290766#M77179</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56277"&gt;@junior_r&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I configure HA for data link I use Ethernet when devices are directly connected to each other, but sometimes in the field I see people using IP for transport but the devices are directly connected to each other. Why are they doing this? There is no reason to do it unless it needs to route. Can someone help me understand there logic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've got a A/P 5220 pair split between DCs that are over 500 miles apart.&amp;nbsp; Latency between both DCs is &amp;lt; 20ms and we have no issues.&amp;nbsp; In our case using IP allows for DC redundancy via 2 geographically separated DCs.&amp;nbsp; The networks for both HA1/2 are just L2 networks with no router so the FWs talk directly 2 each other.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 13:36:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290766#M77179</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-10-01T13:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: HA Data Link Ethernet  vs IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290852#M77192</link>
      <description>&lt;P&gt;Are you using HSCI ports for HA2 Data links?&lt;/P&gt;&lt;P&gt;Which SFP are you using for HA2 Data links?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 02:48:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290852#M77192</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-10-02T02:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: HA Data Link Ethernet  vs IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290872#M77198</link>
      <description>&lt;P&gt;HSCI: no, we are using AUX ports and a couple of regular SFP+ ports (eth1/5 and eth1/6)&lt;BR /&gt;Which SFP: since we need "colored" DWDM links, we are using Solid Optics Cisco-compatible 10Gbit ZR ones.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 06:56:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290872#M77198</guid>
      <dc:creator>michelealbrigo</dc:creator>
      <dc:date>2019-10-02T06:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: HA Data Link Ethernet  vs IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290954#M77215</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Are you using HSCI ports for HA2 Data links?&lt;/P&gt;&lt;P&gt;Which SFP are you using for HA2 Data links?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Just using the embedded copper port on the 5220.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 19:02:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-data-link-ethernet-vs-ip/m-p/290954#M77215</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-10-02T19:02:22Z</dc:date>
    </item>
  </channel>
</rss>

