<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Active HA on PAN 4.x in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13456#M9871</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm sorry because short of english.&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US"&gt;So It seem to be that my question has not delivered correctly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i want is not general concept of PAN's Active Active HA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;directly speaking....&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;What is difference between juniper Active-Active HA and Palo Alto Active-Active HA without L4 switch?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The very important thing for Active-Active HA is that there is no Layer 4 switch. &lt;BR /&gt;without Layer 4 switch!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Juniper is divided internally when deploy Active-Active HA like attached diagram.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Each firewall needs many routing path to make an active-active HA and, If network complex, it needs lots of routing. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;One of another issue is performance. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;PAN is very similar with Juniper. So I’d like to know whether PAN has same issue with juniper on Active-Active.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;i think you may know much of problem of Juniper on Active Active HA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Please let me know what kind of issue PAN has from Active-Active HA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Also let me know what are the very important things to deploy active-active HA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Thanks, &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Eugene. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Mar 2011 12:23:08 GMT</pubDate>
    <dc:creator>willstech</dc:creator>
    <dc:date>2011-03-30T12:23:08Z</dc:date>
    <item>
      <title>Active Active HA on PAN 4.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13453#M9868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; &lt;SPAN lang="EN-US"&gt;PAN 4.x is supporting Active-Active High availability.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Clearly, most firewalls also support Active-Active HA but, they need Layer-4 switch to get full performance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;In other words, most of firewalls also support Active-Active, but it is in name only in the real network world without Layer-4 switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;How about Paloalto on Active-Active?&amp;nbsp; PAN also need Layer-4 switch?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;What is the best way to deploy Active-Active HA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Could you tell me that how it works, if don't need layer-4 switch?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;I’m looking for smart answers. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt;Thanks, &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Eugene. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2011 09:59:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13453#M9868</guid>
      <dc:creator>willstech</dc:creator>
      <dc:date>2011-03-29T09:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Active Active HA on PAN 4.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13454#M9869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;Hi Eugene&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;This document may prove helpfull: &lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1756"&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;https://live.paloaltonetworks.com/docs/DOC-1756&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;Page 7 describes our behavior in vwire, pages 8 and 9 our layer 3 behavior.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;Basically, for vwire you will need layer 3 devices as we act as a wire. In L3 we support 2 modes of operation: Floating IP and ARP load sharing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;Floating IP assigns a/multiple VIP per gateway and these can be used by hosts in the network as gateway&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;In case of failover the VMAC to this VIP is transported to the other peer via gratuitous ARP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;In ARP load sharing a VIP is shared among the HA peers, but each with their individual VMAC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;The device that responds to the ARP request is determined by computing a hash or modulo of the source IP address of the ARP request.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;In case of failover the VMAC is transported to the remaining peer via gratuitous ARP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2011 12:36:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13454#M9869</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2011-03-29T12:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Active Active HA on PAN 4.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13455#M9870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;small correction:&lt;/P&gt;&lt;P&gt;In floating IP each device has a unique VMAC and in case of failover the VIP is moved to the active peer's VMAC using gratuitous ARPs sent out from the active member, the VMAC itself does not move &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2011 16:12:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13455#M9870</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2011-03-29T16:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Active Active HA on PAN 4.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13456#M9871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm sorry because short of english.&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US"&gt;So It seem to be that my question has not delivered correctly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i want is not general concept of PAN's Active Active HA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;directly speaking....&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;What is difference between juniper Active-Active HA and Palo Alto Active-Active HA without L4 switch?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The very important thing for Active-Active HA is that there is no Layer 4 switch. &lt;BR /&gt;without Layer 4 switch!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Juniper is divided internally when deploy Active-Active HA like attached diagram.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Each firewall needs many routing path to make an active-active HA and, If network complex, it needs lots of routing. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;One of another issue is performance. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;PAN is very similar with Juniper. So I’d like to know whether PAN has same issue with juniper on Active-Active.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;i think you may know much of problem of Juniper on Active Active HA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Please let me know what kind of issue PAN has from Active-Active HA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Also let me know what are the very important things to deploy active-active HA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Thanks, &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Eugene. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Mar 2011 12:23:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13456#M9871</guid>
      <dc:creator>willstech</dc:creator>
      <dc:date>2011-03-30T12:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Active Active HA on PAN 4.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13457#M9872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;anybody doesn't explain me about my quesiton??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm wanting for answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Eugene&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Apr 2011 07:15:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13457#M9872</guid>
      <dc:creator>willstech</dc:creator>
      <dc:date>2011-04-04T07:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Active Active HA on PAN 4.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13458#M9873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Eugene,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe your question was answered above with ARP Load Sharing.&amp;nbsp; This does not require an L4 switch as it shares the load between the active units automatically.&amp;nbsp; This really only works well with directly connected hosts initiating traffic outbound.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The intention for Active/Active HA is not to share the load for higher performance but to address asymmetric routing scenarios. The directly connected HA3 links in the cluster will make sure traffic is correctly forwarded in cases where the traffic was delivered to the wrong firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may need to have a further discussion with your local SE to get more information on how to design and configure an Active/Active cluster if you find that design is really necessary.&amp;nbsp; Try to stick with an Active/Passive design, if possible, as it is much more simple to design, config, and troubleshoot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Apr 2011 17:48:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13458#M9873</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-04-04T17:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: Active Active HA on PAN 4.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13459#M9874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi kelly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've got answer from you against most of my quesitons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Eugene.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 05:25:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-on-pan-4-x/m-p/13459#M9874</guid>
      <dc:creator>willstech</dc:creator>
      <dc:date>2011-04-07T05:25:11Z</dc:date>
    </item>
  </channel>
</rss>

