About Active-Active on Vwire

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

About Active-Active on Vwire

L3 Networker

Hello guys.

I tested for now about active-active pair on vwire mode that is simplest deployment I know. but I could not find that more information for active-active HA pair on vwire.

I wonder about that A-A vwire needs ACTIVE-ACTIVE configuration such as HA3 packet forwarding, Session owner selection, Session Setup. I guess that are not needed but I can not confirm.

Please give me some guideline for A-A on vwire that are need HA3 packet forwarding, Session owner, Session Setup configuration or not. if it yes, why does A-A need above configuration.

Thanks.

Regards.

Roh.

1 accepted solution

Accepted Solutions

Retired Member
Not applicable

There should not be a need to forward traffic per se with A-A v-wire. This is because v-wire basically should always forward packets ingressing on one v-wire link to the other. The situation where a packet may need to traverse HA3 link would be if peer which receives the traffic is not the active owner of the session. In that case the packet would traverse HA3 to the other peer, get processed, then traverse HA3 back again to the receiving peer.

Hope that clears things up a bit.

-Richard

View solution in original post

5 REPLIES 5

L3 Networker

The HA3 link is used for packet forwarding between the session owner and the session setup device in an active-active cluster. HA3 link isa layer2 link and uses MAC-in-MAC encapsulation. Aggregate interfaces can be configured as a HA3 link on the PA-5000 and PA-4000 Series. This also provides redundancy of HA3 link. The interface that will be used as HA3 link must be set as type HA.

Hope this helps.

Hi ukhapre

Thank you for reply.

I think that HA3 packet forwarding should not configured on vwire A-A environment. right?

Thank you again.

Regards.

Roh.

Retired Member
Not applicable

There should not be a need to forward traffic per se with A-A v-wire. This is because v-wire basically should always forward packets ingressing on one v-wire link to the other. The situation where a packet may need to traverse HA3 link would be if peer which receives the traffic is not the active owner of the session. In that case the packet would traverse HA3 to the other peer, get processed, then traverse HA3 back again to the receiving peer.

Hope that clears things up a bit.

-Richard

Another point to be think about in any active-active setup:

If traffic enters a port on device A it can never egress from the Active-Active cluster from ANY port on device B.

HA3 is used to forward packets from the active-secondary device to the active-primary device so that they can be evaluated and scanned against the configured security policy.

-Benjamin

A final point to consider:

If you are considering deploying Active-Active you should be talking to your Sales Engineer to choose the proper design for implementing this feature in your environment. In some cases you may discover that an Active-Passive setup is more appropriate for your network.

-Benjamin

  • 1 accepted solution
  • 8571 Views
  • 5 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!