<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA traffic through Cisco Switch in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308525#M80032</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72491"&gt;@AvinashKukkapalli&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Attached screen shots for reference&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-29 at 9.32.26 PM.png" style="width: 990px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23708i23407E23CBF75665/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-29 at 9.32.26 PM.png" alt="Screen Shot 2020-01-29 at 9.32.26 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-29 at 9.32.14 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23709i6136AA257315642A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-29 at 9.32.14 PM.png" alt="Screen Shot 2020-01-29 at 9.32.14 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I refer you to my posts in this thread.&amp;nbsp;&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/PA-3260-and-using-non-dedicated-as-HA1-interface/td-p/308152" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/PA-3260-and-using-non-dedicated-as-HA1-interface/td-p/308152&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you trying to use a different pot for HA-1 because you need fiber?&amp;nbsp; HA-1 has to be used on the dedicated port.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2020 16:11:24 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2020-01-29T16:11:24Z</dc:date>
    <item>
      <title>HA traffic through Cisco Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308491#M80023</link>
      <description>&lt;P&gt;Hi Team ,&lt;BR /&gt;Can we route HA traffic between two 3260 firewalls through cisco switch using L2 vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;My requirement is to run firewalls in HA and devices will be in different buildings. Buildings are connected with dark fiber. As PAN dedicated HA ports are ethernet i have to use another converter or switch to make them communicate in HA ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;i did l2 vlan on 9500 switch but HA1 never comes up.&lt;/P&gt;&lt;P&gt;Can we do like this?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 14:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308491#M80023</guid>
      <dc:creator>AvinashKukkapalli</dc:creator>
      <dc:date>2020-01-29T14:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: HA traffic through Cisco Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308500#M80024</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72491"&gt;@AvinashKukkapalli&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi Team ,&lt;BR /&gt;Can we route HA traffic between two 3260 firewalls through cisco switch using L2 vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;My requirement is to run firewalls in HA and devices will be in different buildings. Buildings are connected with dark fiber. As PAN dedicated HA ports are ethernet i have to use another converter or switch to make them communicate in HA ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;i did l2 vlan on 9500 switch but HA1 never comes up.&lt;/P&gt;&lt;P&gt;Can we do like this?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Technically no, but you can switch the traffic...Ok, I'm done splitting hairs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You 10000% can do this.&amp;nbsp; As long as both switches participate in the same layer 2 domain it should work without issue.&amp;nbsp; (This would also mean that the link the switches are connected has the access VLAN on the trunk the HA-1 ports are on)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Say you have FW-1 connected to SW-1 with the FW-1 HA-1 with the IP of 10.10.10.1 on an Access VLAN 10 to SW-1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You'd need FW-2 connected to SW-2 with the FW-2 HA-1 configured with the IP of 10.10.10.2 on Access VLAN 10 to SW-2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would do the same for HA-2&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 15:19:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308500#M80024</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2020-01-29T15:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: HA traffic through Cisco Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308503#M80026</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;HA1 syncs configuration and heartbeats, it uses dedicated-ha1a/ha1b ports (by default)&lt;/P&gt;&lt;P&gt;HA2 syncs the session table, it uses a dedicated HSCI port (10gb fiber)&lt;/P&gt;&lt;P&gt;You want both up for proper High Availability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can assign a Dataplane port to be of type 'HA' and then you can use it instead of the dedicated HA ports (it will be available in the drop down list under HA1/HA1 backup/HA2/HA2 backup).&lt;/P&gt;&lt;P&gt;This can give you the option to use ethernet1/19 as type HA, used by HA1, connected over a fiber link with appropriate GBIC on both sides thus avoiding a converter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configuration wise:&lt;/P&gt;&lt;P&gt;Firewall-1&lt;/P&gt;&lt;P&gt;Control Link (HA1) IPv4: 1.1.1.1 / 255.255.255.248&lt;/P&gt;&lt;P&gt;Peer HA1 IP Address (in the Setup page): 1.1.1.2&lt;/P&gt;&lt;P&gt;Firewall-2&lt;/P&gt;&lt;P&gt;Control Link (HA1) IPv4: 1.1.1.2 / 255.255.255.248&lt;/P&gt;&lt;P&gt;Peer HA1 IP Address (in the Setup page): 1.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a bit tricky to explain all the possible scenarios, I hope it was clear. Just remember that each FW needs to know the IP address of it's peer for HA1 to come up. Lastly, use HA1 backup as management port and put 'Backup Peer HA1 IP Address=MGMT-IP of other FW.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 14:57:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308503#M80026</guid>
      <dc:creator>ShaiW</dc:creator>
      <dc:date>2020-01-29T14:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: HA traffic through Cisco Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308520#M80030</link>
      <description>&lt;P&gt;I changed data port type to HA but i never get that port in dropdown for HA1 , Only for HA2 i am able to select that data port..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i used L2 vlan but that is not helping&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 15:55:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308520#M80030</guid>
      <dc:creator>AvinashKukkapalli</dc:creator>
      <dc:date>2020-01-29T15:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: HA traffic through Cisco Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308523#M80031</link>
      <description>&lt;P&gt;Attached screen shots for reference&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-29 at 9.32.26 PM.png" style="width: 990px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23708i23407E23CBF75665/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-29 at 9.32.26 PM.png" alt="Screen Shot 2020-01-29 at 9.32.26 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-29 at 9.32.14 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23709i6136AA257315642A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-29 at 9.32.14 PM.png" alt="Screen Shot 2020-01-29 at 9.32.14 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 16:03:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308523#M80031</guid>
      <dc:creator>AvinashKukkapalli</dc:creator>
      <dc:date>2020-01-29T16:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: HA traffic through Cisco Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308525#M80032</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72491"&gt;@AvinashKukkapalli&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Attached screen shots for reference&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-29 at 9.32.26 PM.png" style="width: 990px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23708i23407E23CBF75665/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-29 at 9.32.26 PM.png" alt="Screen Shot 2020-01-29 at 9.32.26 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-29 at 9.32.14 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23709i6136AA257315642A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-29 at 9.32.14 PM.png" alt="Screen Shot 2020-01-29 at 9.32.14 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I refer you to my posts in this thread.&amp;nbsp;&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/PA-3260-and-using-non-dedicated-as-HA1-interface/td-p/308152" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/PA-3260-and-using-non-dedicated-as-HA1-interface/td-p/308152&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you trying to use a different pot for HA-1 because you need fiber?&amp;nbsp; HA-1 has to be used on the dedicated port.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 16:11:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308525#M80032</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2020-01-29T16:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: HA traffic through Cisco Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308536#M80039</link>
      <description>&lt;P&gt;I am good , i see one typo error for peer ip.&lt;/P&gt;&lt;P&gt;thanks for all help&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 16:30:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-traffic-through-cisco-switch/m-p/308536#M80039</guid>
      <dc:creator>AvinashKukkapalli</dc:creator>
      <dc:date>2020-01-29T16:30:23Z</dc:date>
    </item>
  </channel>
</rss>

