Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

2X of PA820 Active/ Passive Design question

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

2X of PA820 Active/ Passive Design question

L2 Linker

Hi All

 

After some advice, planning to have 2 X PA820 pairs of Active/ Passives, Inner and outer firewalls protecting some internal networks.

 

See the diagram, Does the HA2 link pass data plane traffic at all?  Or can it?

 

There could be a scenario that one set of FW's can failover and the primary unit of one trying to speak to the standby unit of the other.  

Or is the only solution to put a switch in between the green cables FW Connect to stop this issue?

 

Capture.JPG

 

 

Thanks All

 

21 REPLIES 21

Thanks for that, so I  will use the Management ports.

Yep we are waiting for training costs, 

 

I would manage both pairs via the management address from Panorama?

Yes.  It is possible to change this behavior, but you would be locking yourself out of the passive node.  Stick with the management interfaces and you'll be fine.

Great, thanks for the advice BTW,

 

I should be able to keep the interface on the Palo Alo set as Layer 3 shouldnt i?   Or will I have to change to a L2 interface ? I need to be able to have a IP address on the interface for the static routing.

 

L2 VLAN, vlan id 555 for example, and all 4 ports will sit in that VLAN.

I highly recommend using Layer 3 sub-interfaces instead of vlan interfaces unless you've got some strange Layer 2 requirements.

Cool will setup L3 sub interfaces, and tag the vlan to the correct access vlan defined on the switch 

or i could fully mesh alll 4 Palos and have two sets of static routes.....but you suggest going via the switch?

  • 9715 Views
  • 21 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!