<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active/passive vs active/active recommendations in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290951#M77212</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The big thing to consider is asymentric routing. If you have the need then A/A, if not then A/P.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 02 Oct 2019 18:55:00 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-10-02T18:55:00Z</dc:date>
    <item>
      <title>Active/passive vs active/active recommendations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290714#M77168</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are about to work on a Paloalto cluster deployment, which will be sitting next to the internet (we will have two separate providers) and we need to make the decision whether we configure it as A/A or A/P.&lt;/P&gt;&lt;P&gt;I keep reading in quite some places (forums and so) that A/P is Paloalto preferred way. That is also my first option, but I would like to have some official documentation to support that decision. Does anyone know where I can find such documentation from Paloalto, where they discuss A/P against A/A?&lt;/P&gt;&lt;P&gt;(I have been able to find the technical documentation of each of the cases, as well as their requirements, but not a specific discussion detailing kind of pros and cons of each of them).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 08:26:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290714#M77168</guid>
      <dc:creator>jorgebarba</dc:creator>
      <dc:date>2019-10-01T08:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Active/passive vs active/active recommendations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290734#M77171</link>
      <description>&lt;P&gt;Not sure you will find any documented reasons but basically..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You don't gain much from A/A other than more throughput during normal running, but your not running N+1 so if one FW dies your under capacity. The added complexity also makes it far more difficult to implement successfully.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hence a properly sized A/P N+1 is the recommended.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 09:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290734#M77171</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-10-01T09:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Active/passive vs active/active recommendations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290767#M77180</link>
      <description>&lt;P&gt;Are you utilizing any dynamic routing protocols with you service providers (and internally)?&amp;nbsp; You might want to consider A/A.&amp;nbsp; What you will learn is this can be very beneficial but will require a lot of setup on you part with a good working knowledge of BGP/OSPF/etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No dynamic routing protocols on either side?&amp;nbsp; Stick with A/P.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 13:34:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290767#M77180</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-10-01T13:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Active/passive vs active/active recommendations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290776#M77183</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52704"&gt;@jorgebarba&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are about to work on a Paloalto cluster deployment, which will be sitting next to the internet (we will have two separate providers) and we need to make the decision whether we configure it as A/A or A/P&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;Thanks a lot in advance&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;In our deployment we have 3 independent&amp;nbsp; ISPs across 2 DCs and we run A/P.&amp;nbsp; As others have stated an A/A deployment is primarily about throughput.&amp;nbsp; If you become reliant upon that second firewall's throughput then when you upgrade or a failure occurs you're environment is now degraded in an A/P deployment you're at N+1 which makes for a much more stable environment.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 13:44:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290776#M77183</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-10-01T13:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active/passive vs active/active recommendations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290779#M77184</link>
      <description>&lt;P&gt;Thanks all for the replies.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107910"&gt;@jeremy.larsen&lt;/a&gt;, indeed we will be running BGP to the internet and (most likely) OSPF internally. But the point is that I do not really see those benefits anyway, in setting the cluster up as A/A. Or say it other way, I do not see any potential benefit that would pay off the rather important increase in complexity (not that it is an issue itself, but it also would complicate any troubleshooting when the time comes, for the NOC and so).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, thanks all for providing your inputs. That's kind of what I am looking for, to gather a list of pros and cons of each of the two options, to make the final decision.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 15:08:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290779#M77184</guid>
      <dc:creator>jorgebarba</dc:creator>
      <dc:date>2019-10-01T15:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Active/passive vs active/active recommendations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290817#M77188</link>
      <description>&lt;P&gt;I've done both.&amp;nbsp; A/A is definitely cool but requires a lot of planning and a deep understanding of what you are doing.&amp;nbsp; If you want BGP to handle the failover for inbound services (ie: website, etc) then A/A is the way to go.&amp;nbsp; Or you can drop HA and use Load Balancers to handle your firewalls and all the routing decisions.&amp;nbsp; If you have something like an F5 handing failover using DNS and no IPs are getting moved between locations, then use good 'ole A/P and call it a day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Just my 2 cents&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 20:56:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290817#M77188</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-10-01T20:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Active/passive vs active/active recommendations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290951#M77212</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The big thing to consider is asymentric routing. If you have the need then A/A, if not then A/P.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 18:55:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/290951#M77212</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-10-02T18:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Active/passive vs active/active recommendations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/291088#M77244</link>
      <description>&lt;P&gt;Agreed,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry I didn't state this in my previous post.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2019 13:23:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/291088#M77244</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-10-03T13:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: Active/passive vs active/active recommendations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/292082#M77344</link>
      <description>&lt;P&gt;Thanks all again for your input.&lt;/P&gt;&lt;P&gt;In fact, I think I still opt more for the A/P solution but we will explore the two options in our particular environment and will decide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 07:10:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-vs-active-active-recommendations/m-p/292082#M77344</guid>
      <dc:creator>jorgebarba</dc:creator>
      <dc:date>2019-10-09T07:10:32Z</dc:date>
    </item>
  </channel>
</rss>

