11-24-2015 02:37 PM
I am currently working on a network redesign project with all Cisco gear. Our network engineer is opting for a complete HSRP Active/Active environment. According to all deployment documentation, HA Active/Passive seems to be the preferred methed for the Palo Alto's. I see that the PA's do support A/A HA using VRRP, so I do not see a configuration issue. Can someone provide the pro's and con's of deploying the PA's in an A/P vs. A/A environment? Are there any performance implications? Are there any issues when using the PA's in an A/A configuration for VPN termination, etc...?
07-23-2019 08:01 AM
If you are using ECMP what is the point os HSRP? Doesn't that kind of defeat the purpose of ECMP by forcing your path one direction?
07-23-2019 08:04 AM
I do not follow?
Each active hsrp peer is connected to each palo alto, so any routes beyond the palo alto can be reach through both palo altos.
07-23-2019 08:15 AM
Full mesh iBGP so Palo1 (172.16.63.3) knows that network 192.168.21.0/24 lives at Core01 (172.16.63.1) and Core02 (172.16.63.2), same for Palo2.
But now I think I see what you are saying.....the traffic is only going to be forwarded to the active peer for that hsrp group correct? I wonder if I am seeing issues because its trying to send to both peers? So my 9500s are the only ones that seem to need to use ecmp and not the palos.
But I have things connected northbound to both palos which ecmp would be good for..So not sure.
07-23-2019 08:19 AM
I'm just saying usually you don't mix both HSRP and ECMP. HSRP - Layer 2 failover mechanism. ECMP - Layer 3 load balancing mechanism.
07-23-2019 08:20 AM
Have you enabled ECMP on the Palos? If you are using iBGP instead of eBGP, there are extra hoops to jump through when enabling ECMP.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!