<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA4 Clustering to present a single NAT IP  across two Data Centres in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha4-clustering-to-present-a-single-nat-ip-across-two-data/m-p/435960#M96119</link>
    <description>&lt;P&gt;You use a load balancer sandwich where the northern/outside LB is floating the IP between the DC connections to the NGFWs. LBs behind the NGFWs to keep flow symmetric (or rerouting when the wire fails).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is, you need the DC LBs to be connected to the opposing NGFWs as well as their local, and both DC NGFWs to the northern LB.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Sep 2021 18:54:38 GMT</pubDate>
    <dc:creator>LAYER_8</dc:creator>
    <dc:date>2021-09-22T18:54:38Z</dc:date>
    <item>
      <title>HA4 Clustering to present a single NAT IP  across two Data Centres</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha4-clustering-to-present-a-single-nat-ip-across-two-data/m-p/429384#M94899</link>
      <description>&lt;P&gt;Can anyone who is using the HA4 cluster in production, to present the same external NAT IP across 2 data centers give any advice on how they are doing the routing.&amp;nbsp; I saw in the docs that some of the security functions don't work if the traffic is asymmetric.&amp;nbsp; Obviously the easy answer is to push all the traffic to one DC.&amp;nbsp; Is that how people do it, or is there a way to load balance across them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am keen to hear about peoples experience with the feature and if they have had any issues with it.&amp;nbsp; Currently I have two separate IP ranges for the two DC's and flip flop between them, but that is a pain.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 10:06:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha4-clustering-to-present-a-single-nat-ip-across-two-data/m-p/429384#M94899</guid>
      <dc:creator>Rich.H</dc:creator>
      <dc:date>2021-08-26T10:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: HA4 Clustering to present a single NAT IP  across two Data Centres</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha4-clustering-to-present-a-single-nat-ip-across-two-data/m-p/435553#M96082</link>
      <description>&lt;P&gt;It's important to note that HA Clustering is not the same thing as Active/Active HA. You are correct in that there is no L7 inspection support for asymmetrical traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My customers using this feature are from a failover / disaster recovery scenario, so not load balancing traffic across two datacenters.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are trying to utilize it for horizontal scaling to get the above scenario working we would recommend a load balancer sandwich, which is another way of saying NAT'ing the DCs to be the same public IP and load balancing with HA Clustering is not a supported use case at this time, but with additional devices you could achieve the functionality.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 16:15:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha4-clustering-to-present-a-single-nat-ip-across-two-data/m-p/435553#M96082</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-09-21T16:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: HA4 Clustering to present a single NAT IP  across two Data Centres</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha4-clustering-to-present-a-single-nat-ip-across-two-data/m-p/435825#M96104</link>
      <description>&lt;P&gt;Failover/DR is my primary driver for this feature.&amp;nbsp; I want the same IP to be used at both of the DCs so that it doesn't affect the IP address that our partners have white listed.&amp;nbsp; What I am unsure of is if the address is pinned to one site or floating, how do we make the inside and outside routing line up so things are symetric&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 14:07:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha4-clustering-to-present-a-single-nat-ip-across-two-data/m-p/435825#M96104</guid>
      <dc:creator>Rich.H</dc:creator>
      <dc:date>2021-09-22T14:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: HA4 Clustering to present a single NAT IP  across two Data Centres</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha4-clustering-to-present-a-single-nat-ip-across-two-data/m-p/435960#M96119</link>
      <description>&lt;P&gt;You use a load balancer sandwich where the northern/outside LB is floating the IP between the DC connections to the NGFWs. LBs behind the NGFWs to keep flow symmetric (or rerouting when the wire fails).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is, you need the DC LBs to be connected to the opposing NGFWs as well as their local, and both DC NGFWs to the northern LB.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 18:54:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha4-clustering-to-present-a-single-nat-ip-across-two-data/m-p/435960#M96119</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-09-22T18:54:38Z</dc:date>
    </item>
  </channel>
</rss>

