<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA-system separated with two datacenters in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11460#M8446</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The last I heard, this is not officially supported.&amp;nbsp; However, if one did do it, two pairs of 100Mbs media converters would be the way to go.&amp;nbsp; Hypothetically.&amp;nbsp; You can also throw them into a layer-2 DEDICATED VLAN, if you don't have dedicated fiber between the devices.&amp;nbsp; You need to make sure latency is very low though, or you're going to end up with both FW's going active.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Apr 2013 18:10:32 GMT</pubDate>
    <dc:creator>bhelman</dc:creator>
    <dc:date>2013-04-22T18:10:32Z</dc:date>
    <item>
      <title>HA-system separated with two datacenters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11451#M8437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Man have two datacenters and there are about 15-20km between them. The datacenters are connected by dark fiber with 1Gb bandwidth, is it possible to make HA-system to this setup? I mean so, that one of the PA-unit is in the primary datacenter and another is in the secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Janne&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 09:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11451#M8437</guid>
      <dc:creator>jjormalainen</dc:creator>
      <dc:date>2010-04-13T09:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: HA-system separated with two datacenters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11452#M8438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Janne,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have dark fiber and are carring the vlans associated to the security zones &amp;amp; HA1, HA2 accross the fiber it should work correctly.&lt;/P&gt;&lt;P&gt;Normally the latency at that distance over dark fiber is very low, therefore you should be ok.&lt;/P&gt;&lt;P&gt;What technology will you be using to light the fiber? It should provide you with L1 connectivity between both firewalls effectively as if they were conected across a L2 switch.&lt;/P&gt;&lt;P&gt;From the high availability perspective it might not be optimal becuase if the fiber or equipment to light it fails you will end up in a split brain condition.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps, and let us knwo if your testing goes Ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, Jose Muniz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 12:48:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11452#M8438</guid>
      <dc:creator>jmuniz</dc:creator>
      <dc:date>2010-04-13T12:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: HA-system separated with two datacenters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11453#M8439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jose,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for answering. I thought also that latency is not a problem at that distance. When I have tested this, I'll let you know the results, hopefully before summer &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt; It depends on the customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;--Janne&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Apr 2010 06:44:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11453#M8439</guid>
      <dc:creator>jjormalainen</dc:creator>
      <dc:date>2010-04-15T06:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: HA-system separated with two datacenters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11454#M8440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It'll work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We carry HA-1 and HA-2 across different VLANs, and haven't had a problem yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Apr 2010 15:14:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11454#M8440</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2010-04-22T15:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: HA-system separated with two data centers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11455#M8441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This thread is a year old, but I figured I'd try anyway ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you say you are carrying HA1/HA2 over two different vlans, I'm assuming you mean you are plugging those ports into switch gear that then goes over some kind of WAN and is reversed on the other side.&amp;nbsp; Since it's plugged in to a switch port, you don't need the cross-over cable.&amp;nbsp; 1) what speed are the ports (I have a pair of PA-4020's and I'm not seeing anything that tells me if they are 10, 100 or 1000)?&amp;nbsp; 2) Did you consider using media converters so the traffic was physically isolated (so a switch reboot due to anything as basic as a config change or code upgrade doesn't break your link)?&amp;nbsp; I don't know that I want to burn off 4 extra strands of fiber, so VLAN's may be the better way to go .. I'm just asking the question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, it's been a year since you said you haven't had any issues.&amp;nbsp; How has the past year treated you re: the HA over VLAN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Apr 2011 15:11:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11455#M8441</guid>
      <dc:creator>bhelman</dc:creator>
      <dc:date>2011-04-29T15:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: HA-system separated with two data centers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11456#M8442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Everything we have is set to auto. I think the PA-4000 has dedicated HA ports, our PA-2050 we had to designate two ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, we had sucess with carrying other VLANs across that link with no problem. It's nearly been 18 months now. I've only seen HA2 go down once, (HA2 is connected to the dataplane and caries the session table to the other firewall, HA1 is connected to the mangement plane and caries the configs and heartbeat.) but it came right back up. It's generally the fault of the ISP. I'll see a few errors on the interfaces between the core switches.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Apr 2011 15:19:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11456#M8442</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2011-04-29T15:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: HA-system separated with two data centers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11457#M8443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are building a new data center across the street from the old one (probably 300 yards).&amp;nbsp; Even though that's not a great separation, it's better than using the same room so I'm considering leaving 1 unit in the old data center and moving 1 to the new.&amp;nbsp;&amp;nbsp; I have my own fiber between the buildings, so fiber count is not an issue right now.&amp;nbsp; I think I'm more inclined to use media converters though, just because of the switch-maintenance issue.&amp;nbsp; The problem with that .. I need to figure out the HAx port speeds so I get the right fiber/copper converters (I don't want to buy 100/1000 if I can only use 100, but it sounds to me like 100 is probably overkill for the amount of data anyway).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is all good information.&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Apr 2011 15:53:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11457#M8443</guid>
      <dc:creator>bhelman</dc:creator>
      <dc:date>2011-04-29T15:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: HA-system separated with two datacenters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11458#M8444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there official specs available from PA regarding speed, latency/distance&amp;nbsp; for an A/P &amp;amp; A/A cluster split over two sites?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Joris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Apr 2013 09:41:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11458#M8444</guid>
      <dc:creator>jorisVD</dc:creator>
      <dc:date>2013-04-22T09:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: HA-system separated with two datacenters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11459#M8445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would also like to see that spec! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Apr 2013 17:46:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11459#M8445</guid>
      <dc:creator>mfro</dc:creator>
      <dc:date>2013-04-22T17:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: HA-system separated with two datacenters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11460#M8446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The last I heard, this is not officially supported.&amp;nbsp; However, if one did do it, two pairs of 100Mbs media converters would be the way to go.&amp;nbsp; Hypothetically.&amp;nbsp; You can also throw them into a layer-2 DEDICATED VLAN, if you don't have dedicated fiber between the devices.&amp;nbsp; You need to make sure latency is very low though, or you're going to end up with both FW's going active.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Apr 2013 18:10:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-system-separated-with-two-datacenters/m-p/11460#M8446</guid>
      <dc:creator>bhelman</dc:creator>
      <dc:date>2013-04-22T18:10:32Z</dc:date>
    </item>
  </channel>
</rss>

