Palo Alto firewall cluster operating in Active/Active HA mode and a Check Point Quantum 29200 ElasticXL Security Group

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Palo Alto firewall cluster operating in Active/Active HA mode and a Check Point Quantum 29200 ElasticXL Security Group

L0 Member

Hello Palo Alto Community,

We are designing a high-availability, high-throughput connection between a
Palo Alto firewall cluster operating in Active/Active HA mode and a Check
Point Quantum 29200 ElasticXL Security Group.

The proposed topology is:

   - Two Palo Alto firewalls operating in Active/Active HA mode.
   - Two Check Point Quantum 29200 firewalls operating as an ElasticXL
   Security Group with SMO.
   - Four physical 10-Gbps interconnections in a full-mesh design:
      - Palo Alto Firewall 1 to Check Point Member 1
      - Palo Alto Firewall 1 to Check Point Member 2
      - Palo Alto Firewall 2 to Check Point Member 1
      - Palo Alto Firewall 2 to Check Point Member 2
   - Each Palo Alto firewall is planned to use an Aggregate Ethernet
   interface, while each Check Point member uses a Bond interface.

We would appreciate Palo Alto's best-practice guidance on the following:

   1. What is the recommended Layer 3 routing design between a Palo Alto
   Active/Active cluster and a Check Point ElasticXL Security Group?
   2. Is eBGP or OSPF the preferred dynamic-routing protocol for this
   firewall-to-firewall design?
   3. Should routing neighbors be configured independently on each firewall
   member and each physical/routed link?
   4. Is it supported and recommended to create an LACP Aggregate Ethernet
   interface between a Palo Alto Active/Active pair and the Check Point
   ElasticXL Security Group across multiple members?
   5. Alternatively, is it better to use separate, non-LACP Layer 3 routed
   links between each Palo Alto firewall and each Check Point member, with
   ECMP and dynamic routing?
   6. How should the design handle session symmetry and return traffic to
   avoid asymmetric routing or session-ownership issues when both platforms
   are running active-active/load-sharing modes?
   7. Are there specific Active/Active HA, Aggregate Ethernet, ECMP, or
   dynamic-routing limitations that we should consider for this topology?

A conceptual diagram is attached. We would appreciate official
documentation, validated design recommendations, and examples from similar
deployments.


Please note: Checkpoint ElasticXL mode uses only a single IP address for
the cluster. However, the Palo Alto firewalls will use separate IP
addresses.

Thank you.

Now, everyone remembers doctors, nurses, pharmacists, and all other healthcare professionals. But no one cares about IT guys who work 24/7 to keep everyone connected....
0 REPLIES 0
  • 113 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!