<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vwire Active Active with ASA HA Pair in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-active-active-with-asa-ha-pair/m-p/345240#M86311</link>
    <description>&lt;P&gt;I have a n HA pair of ASA and will be implementing an HA pair of PANS between the Core and ASAs. I can send a topology if necessary. Currently have a Cisco 3750 layer 3 connected to two separate Cisco 2960s via a trunk link. The2960s are aslo inter-connected via a trunk link. The ASAs are connected to each 2960 via access port. The original idea was to implement the Palo Altos in A/P but it seems easier to implement A/A. Are there any gotchas for this scenario. I know it is best practice and recommended for Vwire A/A in a layer 3 topology only and to make sure spanning-tree is configured properly for layer 2. From what I have read you should not carry the Vwire vlan across the inter-switch trunk but wold this just be for the trunk between the 2960's or all of the trunk links? I would think the traffic would not pass if the vlan is not allowed between the 3750 and 2960 trunks.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Aug 2020 20:39:23 GMT</pubDate>
    <dc:creator>Gene_Barden</dc:creator>
    <dc:date>2020-08-24T20:39:23Z</dc:date>
    <item>
      <title>Vwire Active Active with ASA HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-active-active-with-asa-ha-pair/m-p/345240#M86311</link>
      <description>&lt;P&gt;I have a n HA pair of ASA and will be implementing an HA pair of PANS between the Core and ASAs. I can send a topology if necessary. Currently have a Cisco 3750 layer 3 connected to two separate Cisco 2960s via a trunk link. The2960s are aslo inter-connected via a trunk link. The ASAs are connected to each 2960 via access port. The original idea was to implement the Palo Altos in A/P but it seems easier to implement A/A. Are there any gotchas for this scenario. I know it is best practice and recommended for Vwire A/A in a layer 3 topology only and to make sure spanning-tree is configured properly for layer 2. From what I have read you should not carry the Vwire vlan across the inter-switch trunk but wold this just be for the trunk between the 2960's or all of the trunk links? I would think the traffic would not pass if the vlan is not allowed between the 3750 and 2960 trunks.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 20:39:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-active-active-with-asa-ha-pair/m-p/345240#M86311</guid>
      <dc:creator>Gene_Barden</dc:creator>
      <dc:date>2020-08-24T20:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: Vwire Active Active with ASA HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-active-active-with-asa-ha-pair/m-p/345356#M86318</link>
      <description>&lt;P&gt;I'm imagining a triangle with 2 ASA's dangling from the bottom&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you'll want to set the PAs between the ASAs and the switches&lt;/P&gt;&lt;P&gt;if you like, you could also add vwires on all the trunks but this might be overkill, it sorta depends where those switches connect to and where you need to have security in between&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 11:28:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-active-active-with-asa-ha-pair/m-p/345356#M86318</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-08-25T11:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Vwire Active Active with ASA HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-active-active-with-asa-ha-pair/m-p/345369#M86322</link>
      <description>&lt;P&gt;Here is the physical topology of the scenario. All switch connections south of the Palo are trunk ports with all of the vlans trunked. The link between the 2960s has all vlans trunked except for the primary vlan2 which is the main vlan for the network and to the ASA. I have also attached an A/P scenario adding additional switches north of the Palo connected to the ASA also. Trying to decide which&amp;nbsp;scenario will work best.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Active/Active" style="width: 689px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27495i8A1BDA477FAC595C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Active-Active.png" alt="Active/Active" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Active/Active&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Active/Passive" style="width: 690px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27496i3EE6E8C42F20DB45/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Active-Passive.png" alt="Active/Passive" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Active/Passive&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 12:59:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-active-active-with-asa-ha-pair/m-p/345369#M86322</guid>
      <dc:creator>Gene_Barden</dc:creator>
      <dc:date>2020-08-25T12:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Vwire Active Active with ASA HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-active-active-with-asa-ha-pair/m-p/345370#M86323</link>
      <description>&lt;P&gt;the A/P scenario will be easier to troubleshoot&amp;nbsp; in case there is ever a defect in the network connection, the primary member will also remain active if the ASA dies, being one less failover the sessions need to endure (if the ASA fails over in the A/A scenario, the sessions are handed over to the second ASAs, but also to the second PA. this increases the chances of having a hickup and will have an impact on the time it takes for sessions to transition)&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 13:26:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-active-active-with-asa-ha-pair/m-p/345370#M86323</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-08-25T13:26:24Z</dc:date>
    </item>
  </channel>
</rss>

