<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSec tunnels - Active/Passive OR Active/Active in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnels-active-passive-or-active-active/m-p/307632#M79898</link>
    <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;I'm planning on getting two new Palo Alto firewalls for setting up IPSec tunnels. I think the first tunnel will be a primary tunnel and the second tunnel will be back up. I'm tempted to set up my new firewalls as active/passive HA, to make life easy. But to be sure, please could someone suggest what are the advantages of using active/passive compared to active/active for dual IPSec tunnels?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm going to be using BGP over the IPSec tunnels and BGP to the LAN, so if I go for the active/passive option, it just means i dont have to double up my BGP peers...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any links to the best practices for BGP and IPSec HA would be appreciated... thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jan 2020 02:12:27 GMT</pubDate>
    <dc:creator>Jedi_D</dc:creator>
    <dc:date>2020-01-23T02:12:27Z</dc:date>
    <item>
      <title>IPSec tunnels - Active/Passive OR Active/Active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnels-active-passive-or-active-active/m-p/307632#M79898</link>
      <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;I'm planning on getting two new Palo Alto firewalls for setting up IPSec tunnels. I think the first tunnel will be a primary tunnel and the second tunnel will be back up. I'm tempted to set up my new firewalls as active/passive HA, to make life easy. But to be sure, please could someone suggest what are the advantages of using active/passive compared to active/active for dual IPSec tunnels?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm going to be using BGP over the IPSec tunnels and BGP to the LAN, so if I go for the active/passive option, it just means i dont have to double up my BGP peers...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any links to the best practices for BGP and IPSec HA would be appreciated... thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 02:12:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnels-active-passive-or-active-active/m-p/307632#M79898</guid>
      <dc:creator>Jedi_D</dc:creator>
      <dc:date>2020-01-23T02:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnels - Active/Passive OR Active/Active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnels-active-passive-or-active-active/m-p/307759#M79916</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would say it doesnt matter with regards to a VPN tunnel. I think you have to choose if you actually require an A/A HA scenario. If you can get away with a A/P HA, I would say do that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 22:04:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnels-active-passive-or-active-active/m-p/307759#M79916</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-01-23T22:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnels - Active/Passive OR Active/Active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnels-active-passive-or-active-active/m-p/307772#M79917</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52883"&gt;@Jedi_D&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Agreed with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;;&amp;nbsp;in your situation it doesn't matter if you deploy A/P or A/A as far as the VPN tunnels go, makes no change to how you are going to do things really. There aren't a lot of use cases where I would really recommend an Active/Active Palo Alto deployment to be honest, there are far too many issues that are present in A/A deployments.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 03:17:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnels-active-passive-or-active-active/m-p/307772#M79917</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-01-24T03:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnels - Active/Passive OR Active/Active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnels-active-passive-or-active-active/m-p/307789#M79918</link>
      <description>&lt;P&gt;Thank you people,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I will stick to A/P&lt;/P&gt;&lt;P&gt;I'm going to do BGP as well, and even that can work fine with A/P instead of having 2 separate BGP peers with A/A and BGP metrics.&amp;nbsp;&lt;/P&gt;&lt;P&gt;i'm just wondering why people would have chose A/A then have issues with apps later on...&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 09:18:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnels-active-passive-or-active-active/m-p/307789#M79918</guid>
      <dc:creator>Jedi_D</dc:creator>
      <dc:date>2020-01-24T09:18:21Z</dc:date>
    </item>
  </channel>
</rss>

