High Availability

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

High Availability

L1 Bithead

Hello,

 

I am looking for some assistance in regards to my HA setup. We currently have x2 PAN-3220 devices connected via dedicated HA-1 ports and are fully synchronized currently.

 

We are in the process of moving between floors in our office and will be moving 1 ISP and 1 FW at a time to the new location. My question is, I would like to retain the HA between the firewalls between the floors during the temp split, is this possible when the dedicated HA ports will no longer be physically connected? Can we extend the L2 and trunk the HA subnets across the floors? I have never had to do this before so not sure if it is possible.

 

I was thinking of connecting either end of the HA to a switch on each floor and trunking the VLAN/subent of the HA between them. I am also open to suggestions.

 

Thanks in advance 🙂

1 ACCEPTED SOLUTION

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @PearsonSamuel ,

 

Yes, the HA will work over the network as you describe.  The best practice is to encrypt the data over the network, but in your case it is only temporary.  I do not think it is documented, but a PANW SE told me HA in different locations is supported if the latency is < 20 ms.  He also said that customers have reported that it works fine up to 80-120 ms.

 

During your move, an ISP interface will go down.  You probably will want to disable link monitoring for that interface.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hi @PearsonSamuel ,

 

Yes, the HA will work over the network as you describe.  The best practice is to encrypt the data over the network, but in your case it is only temporary.  I do not think it is documented, but a PANW SE told me HA in different locations is supported if the latency is < 20 ms.  He also said that customers have reported that it works fine up to 80-120 ms.

 

During your move, an ISP interface will go down.  You probably will want to disable link monitoring for that interface.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Hi Tom,

 

Thanks so much for your reply and for your input. This is good to hear that this is supported as this will save us some work (all be it temporary). The fiber link between the floors that will be responsible for trunking the HA subnets through are 10G aggregated links (20G bundle) so latency should be no issue.

 

Thanks!

 

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!