<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HA failover between two geo-separated firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-between-two-geo-separated-firewall/m-p/342165#M85786</link>
    <description>&lt;P&gt;We are going to configure Active-Passive HA for PA3250. Primary and secondary device both at different locations , distance - 25 Kilometer.&lt;/P&gt;&lt;P&gt;Location A ( Primary FW) --- L2 switch -------------P2P link 60 Mbps-------------------------L2 Switch -------Location B ( Secondary FW)&lt;/P&gt;&lt;P&gt;For above scenario , can we use common P2P link for HA1 and HA2 ? We will use non-overlapping subnet for HA1 and HA2 connectivity .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which HA timer setting need to check for heartbeat and ping ? How we can check ms or ping response between primary and secondary firewall for HA1 and HA2 interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Aug 2020 08:52:18 GMT</pubDate>
    <dc:creator>Deepak_K</dc:creator>
    <dc:date>2020-08-05T08:52:18Z</dc:date>
    <item>
      <title>HA failover between two geo-separated firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-between-two-geo-separated-firewall/m-p/342165#M85786</link>
      <description>&lt;P&gt;We are going to configure Active-Passive HA for PA3250. Primary and secondary device both at different locations , distance - 25 Kilometer.&lt;/P&gt;&lt;P&gt;Location A ( Primary FW) --- L2 switch -------------P2P link 60 Mbps-------------------------L2 Switch -------Location B ( Secondary FW)&lt;/P&gt;&lt;P&gt;For above scenario , can we use common P2P link for HA1 and HA2 ? We will use non-overlapping subnet for HA1 and HA2 connectivity .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which HA timer setting need to check for heartbeat and ping ? How we can check ms or ping response between primary and secondary firewall for HA1 and HA2 interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 08:52:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-between-two-geo-separated-firewall/m-p/342165#M85786</guid>
      <dc:creator>Deepak_K</dc:creator>
      <dc:date>2020-08-05T08:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: HA failover between two geo-separated firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-between-two-geo-separated-firewall/m-p/342318#M85815</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62177"&gt;@Deepak_K&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I would really caution against doing this over a P2P link, which I assume would be wireless? The chance that something would take down that link and leave you in a split-brain scenario would be much too high for my liking. That being said, it would absolutely work from a functional aspect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This document will give you everything you could possibly want about failover optimizations, but the piece you'll want to look at is the HA Timer Configuration Considerations. Note, while this document is older, everything on it is still viable.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 21:17:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-between-two-geo-separated-firewall/m-p/342318#M85815</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-08-05T21:17:54Z</dc:date>
    </item>
  </channel>
</rss>

