<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA Firewalls HA Active-Active Routed design with BGP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-ha-active-active-routed-design-with-bgp/m-p/344698#M86224</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139715"&gt;@VarunRao&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I'm also fan of A/S deployment however for this environment, one primary use case of A/A we have is, we have plenty of available bandwidth but a single Active FW is a bottleneck. We occasionally have high volume of data transfer and we can leverage both active path.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2020 01:22:13 GMT</pubDate>
    <dc:creator>yham81</dc:creator>
    <dc:date>2020-08-20T01:22:13Z</dc:date>
    <item>
      <title>PA Firewalls HA Active-Active Routed design with BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-ha-active-active-routed-design-with-bgp/m-p/344129#M86104</link>
      <description>&lt;P&gt;Hello Everyone,&lt;BR /&gt;I'm designing an edge network with Active/Active HA. After reading the PA documentation, I found Active/Active Routed based redundancy design which seems best suited for our environment. However the topology shown in Docs is a square model and I'm thinking to add more links to convert it to full mesh to add more redundancy and fast convergence&amp;nbsp; I wanted to ask what are the pros and cons of full mesh design.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pros of Full mesh ( i can think of): 1) ECMP&amp;nbsp; 2) Fast switchover in case of link failure 3) Tolerate double link failure&lt;/P&gt;&lt;P&gt;Cons of Full mesh: 1) Complexity 2) more physical interfaces 3) Asymetric traffic may cause issue such as traffic leave eth 1/2 but comes back from eth1/4 of the firewalls (assuming eth1/2 &amp;amp; eth1/2 in the same security Zone) and to allow that behavior, I will have to tweak the firewall configuration.&lt;BR /&gt;Please see below both square design and the full mesh design that I intend to proceed with.&lt;/P&gt;&lt;P&gt;I will appreciate the feedback. Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA-AA-Routed-based-Redundancy-Square&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HA-AA-Routed-based-Redundancy-Square.jpg" style="width: 300px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27394i759192F7479A0B2E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="HA-AA-Routed-based-Redundancy-Square.jpg" alt="HA-AA-Routed-based-Redundancy-Square.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA-AA-Routed-based-Redundancy-Full-Mesh&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HA-AA-Routed-based-Redundancy-Full-Mesh.jpg" style="width: 294px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27396iA2E0C10BF7C09804/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="HA-AA-Routed-based-Redundancy-Full-Mesh.jpg" alt="HA-AA-Routed-based-Redundancy-Full-Mesh.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 15:59:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-ha-active-active-routed-design-with-bgp/m-p/344129#M86104</guid>
      <dc:creator>yham81</dc:creator>
      <dc:date>2020-08-16T15:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: PA Firewalls HA Active-Active Routed design with BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-ha-active-active-routed-design-with-bgp/m-p/344246#M86129</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;While I like to keep my networks relatively simple, as you stated there are advantages and disadvantages to either. If you are not concerned with the additional ports used, then go full meshed. The real advantage is device failure. Looks at the diagrams and then pretend a device failed, then find the paths that traffic can flow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 21:13:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-ha-active-active-routed-design-with-bgp/m-p/344246#M86129</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-08-17T21:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA Firewalls HA Active-Active Routed design with BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-ha-active-active-routed-design-with-bgp/m-p/344490#M86183</link>
      <description>&lt;P&gt;Hi Mate,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I may ask, what was your business case for using HA-AA with full-meshed routing? The reason I am asking is we just implemented a topology last weekend HA-AS ecmp load balancing and BGP on the external interface of the firewall to ensure complete usage of both the internet links by the customer. And now it is in production and working like a charm. Maybe if you let me know your purpose of Active-Active setup I can advise you better on it.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 00:02:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-ha-active-active-routed-design-with-bgp/m-p/344490#M86183</guid>
      <dc:creator>VarunRao</dc:creator>
      <dc:date>2020-08-19T00:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: PA Firewalls HA Active-Active Routed design with BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-ha-active-active-routed-design-with-bgp/m-p/344698#M86224</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139715"&gt;@VarunRao&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I'm also fan of A/S deployment however for this environment, one primary use case of A/A we have is, we have plenty of available bandwidth but a single Active FW is a bottleneck. We occasionally have high volume of data transfer and we can leverage both active path.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 01:22:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-firewalls-ha-active-active-routed-design-with-bgp/m-p/344698#M86224</guid>
      <dc:creator>yham81</dc:creator>
      <dc:date>2020-08-20T01:22:13Z</dc:date>
    </item>
  </channel>
</rss>

