IPSec tunnels - Active/Passive OR Active/Active

Reply
Highlighted
L2 Linker

IPSec tunnels - Active/Passive OR Active/Active

Hello Folks,

I'm planning on getting two new Palo Alto firewalls for setting up IPSec tunnels. I think the first tunnel will be a primary tunnel and the second tunnel will be back up. I'm tempted to set up my new firewalls as active/passive HA, to make life easy. But to be sure, please could someone suggest what are the advantages of using active/passive compared to active/active for dual IPSec tunnels?

 

I'm going to be using BGP over the IPSec tunnels and BGP to the LAN, so if I go for the active/passive option, it just means i dont have to double up my BGP peers... 

 

Any links to the best practices for BGP and IPSec HA would be appreciated... thanks

 

 

 

 

 

Highlighted
L7 Applicator

Re: IPSec tunnels - Active/Passive OR Active/Active

Hello,

I would say it doesnt matter with regards to a VPN tunnel. I think you have to choose if you actually require an A/A HA scenario. If you can get away with a A/P HA, I would say do that.

 

Regards,

L7 Applicator

Re: IPSec tunnels - Active/Passive OR Active/Active

@Jedi_D,

Agreed with @OtakarKlier; in your situation it doesn't matter if you deploy A/P or A/A as far as the VPN tunnels go, makes no change to how you are going to do things really. There aren't a lot of use cases where I would really recommend an Active/Active Palo Alto deployment to be honest, there are far too many issues that are present in A/A deployments.

Highlighted
L2 Linker

Re: IPSec tunnels - Active/Passive OR Active/Active

Thank you people, 

I think I will stick to A/P

I'm going to do BGP as well, and even that can work fine with A/P instead of having 2 separate BGP peers with A/A and BGP metrics. 

i'm just wondering why people would have chose A/A then have issues with apps later on...

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!