<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active / Active NAT question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/299123#M78328</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have configured arp load sharing on your FWs, then both device 0 and device 1 would be sending the SNAT through their respective eth1/1 interface.&amp;nbsp;&amp;nbsp; It would not (to the best of my knowledge) use the HA3 to perform asynchronous routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If device 0 fails, then device1 will still have the SNAT on it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What other questions can we answer for you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Nov 2019 15:41:46 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-11-18T15:41:46Z</dc:date>
    <item>
      <title>Active / Active NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/298946#M78294</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To all the A/A users. How have you / Or can you setup SNAT so that all traffic is SNAT'ed to 1 ip .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;very basic example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eth1 - connect to 1.2.3.0/24 - interface address is 1.2.3.2/24 &amp;amp; 1.2.3.3/24 (A/A)&amp;nbsp; 1.2.3.1 arp load balanced&lt;/P&gt;&lt;P&gt;eth2 - connecs to 10.10.10.0/24 interface addrss is 10.10.10.2/24&amp;nbsp; &amp;amp; 10.10.10.3/24 ( A/A) 10.10.10.1 arp load balanced&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy that say every thing from eth2 leaving eth1 get SNAT to 1.2.3.1. how do I do this on A/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2019 10:49:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/298946#M78294</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-11-16T10:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Active / Active NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/298975#M78300</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really believe that for HA A/A you need to have L2 switches upstream/downstream the FWs.&lt;/P&gt;&lt;P&gt;The arp load sharing config allows for a single IP to be shared by both FWs, hence 2 virtual mac addresses.&lt;/P&gt;&lt;P&gt;So the arp table on the L3 switch is going to have 2 entries for the same IP, but with 2 different mac address?&lt;/P&gt;&lt;P&gt;How is that possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_2.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22406i7AFFF7353535DA26/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_2.png" alt="clipboard_image_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on the parity of the source IP, the FWs will load share (not balance) the sessions.&lt;/P&gt;&lt;P&gt;Yet, if the router has a static IP that is even, then only 1 FW would technically handle the inbound traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean you could program the FW to use a SNAT of 1.2.3.1, but I believe that the response traffic would only go to a single FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What other questions can I answer for you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2019 18:37:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/298975#M78300</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-11-16T18:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Active / Active NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/298980#M78305</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get the L2 stuff. this is more around the NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if I have 1 SNAT and say it associated with device 0 ( if I have device 0 and device 1).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if traffic enters device 1 and the rules state to use NAT, it will go to device 0 via the cross connect and then be NAT'ed and then sent out .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if the reverse if a return pack comes in and goes to device 1 it will go to device 0 and be un SNAT and then sent inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so if device 0 fails - that nat will move to device 1 and just work there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that how it works ?&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2019 20:20:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/298980#M78305</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-11-16T20:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: Active / Active NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/299123#M78328</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have configured arp load sharing on your FWs, then both device 0 and device 1 would be sending the SNAT through their respective eth1/1 interface.&amp;nbsp;&amp;nbsp; It would not (to the best of my knowledge) use the HA3 to perform asynchronous routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If device 0 fails, then device1 will still have the SNAT on it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What other questions can we answer for you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 15:41:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/299123#M78328</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-11-18T15:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Active / Active NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/299223#M78345</link>
      <description>&lt;P&gt;Let me expand&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22443i03D9625BF7053226/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;So I have added a diagram - might help.&lt;BR /&gt;So A/A cluster Device0 &amp;amp; Device1&lt;BR /&gt;The relevant link to the doco&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/set-up-activeactive-ha/determine-your-activeactive-use-case/use-case-configure-separate-source-nat-ip-address-pools-for-activeactive-ha-firewalls.html#id5f921ef5-1f92-4111-9d05-c00dd4d19f7a" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/set-up-activeactive-ha/determine-your-activeactive-use-case/use-case-configure-separate-source-nat-ip-address-pools-for-activeactive-ha-firewalls.html#id5f921ef5-1f92-4111-9d05-c00dd4d19f7a&lt;/A&gt;&lt;/P&gt;&lt;P&gt;so my aim is to have 1 SNAT for all traffic that comes from inside (192.168.0.0/16) to outside (eth1).&lt;BR /&gt;The SNAT is 10.0.0.1/32 - I think just having it as a SNAT will make the PA respond to arp requests for it on eth1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;on the inside I have 3 vlans 192.168.1.0/24, 192.168.2.0/24, 192.168.3.0/24. With .1 being the DGW for each lan setup as Arp loading sharing&lt;/P&gt;&lt;P&gt;so if the NAT policy is attached to device 0 my expaction would be for 192.168.1.250 -&amp;gt; 10.10.10.250&lt;BR /&gt;192.168.1.250 -&amp;gt; 192.168.1.1 (goes to device 0)&lt;BR /&gt;device 0 has the NAT pool&lt;BR /&gt;SNAT 10.0.0.1 -&amp;gt; 10.10.10.250&lt;BR /&gt;then response would be 10.10.10.250 -&amp;gt; 10.0.0.1&lt;BR /&gt;so when one of the routers on the internet site does arp 10.0.0.1 device 0 will respond because it has the SNAT policy&lt;BR /&gt;deSNAT 10.10.10.250-&amp;gt;192.168.1.250&lt;/P&gt;&lt;P&gt;That all works fine&lt;/P&gt;&lt;P&gt;So lets look at 192.168.3.250 -&amp;gt; 10.10.10.250&lt;BR /&gt;192.168.1.250 -&amp;gt; 192.168.1.1 (goes to device 1)&lt;BR /&gt;?? What happens here. NAP policy is only active on device 0&lt;BR /&gt;does the packet get send to device 0 via the HA link or ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 22:35:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/299223#M78345</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-11-18T22:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Active / Active NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/299727#M78404</link>
      <description>&lt;P&gt;Hello again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the picture and the detail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are some assumptions you made, that I want to clear up.&lt;/P&gt;&lt;P&gt;With ARP Load sharing, you really cannot force device 0 to own the virtual IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22477iB75A373E30C90D03/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;By definition,&amp;nbsp; arp load sharing means BOTH FWs will own the 192.168.1.1 address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_1.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22478i92479A36DEFBC2FD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_1.png" alt="clipboard_image_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you wanted to do Floating IP, then yes, you could have device 0 own the IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_2.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22479i8C63E0AB38829298/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_2.png" alt="clipboard_image_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would need to configure Floating IP for your outside interfaces, so that 10.0.0.1 is associated with device 0 (as you want).&lt;/P&gt;&lt;P&gt;How would 192.168.3.x get out?&amp;nbsp; You would need to config a 2nd Floating IP for the device1 FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something like this.... (IPs are not the same) but you would get the gist of it...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_3.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22482iF71307515FBD948C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_3.png" alt="clipboard_image_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The idea (according to the picture) is that BOTH FWs are configured with a weighted configuration, so that each device0 or device1 FW could fail, and the other FW outside interfaces would "float" to the other FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 546px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22483iC876A5A4F1899FCB/image-dimensions/546x183/is-moderation-mode/true?v=v2" width="546" height="183" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 16:59:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/299727#M78404</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-11-20T16:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: Active / Active NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/299773#M78414</link>
      <description>&lt;P&gt;HI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just for clarity - yes I understand how arp loading sharing work and depending on which method you use you can predict which device responsed.&amp;nbsp; From memory an increment of 1 in the 4th oct will change the device. this is similar to how arp ip load sharing work in linux - last time i looked. so yes its active on both and the pack actual gets to both its a matter of whcih device responds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But basically you are confirming my original thought. with A/A you can't share 1 SNAT addresses. because if&amp;nbsp; a packet traverses the device that doesn't have the active NAT rule - no NAT Rule would apply.&amp;nbsp; &amp;nbsp;That to me seems like a very big deficiency ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lines up with the doco though and what I got from support and from the SE - I went through this exercise nearly 2 years ago.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 20:27:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-nat-question/m-p/299773#M78414</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-11-20T20:27:20Z</dc:date>
    </item>
  </channel>
</rss>

