Active/Passive vs. Active/Active

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Active/Passive vs. Active/Active

L0 Member

I am currently working on a network redesign project with all Cisco gear. Our network engineer is opting for a complete HSRP Active/Active environment. According to all deployment documentation, HA Active/Passive seems to be the preferred methed for the Palo Alto's. I see that the PA's do support A/A HA using VRRP, so I do not see a configuration issue. Can someone provide the pro's and con's of deploying the PA's in an A/P vs. A/A environment? Are there any performance implications? Are there any issues when using the PA's in an A/A configuration for VPN termination, etc...?


looks like each palo is marking the path to the standby hsrp peer for a vlan as ecmp preferred path. Is this an issue? What does that mean axactly?

Do you recall what had to be done with ecmp in an iBGP mesh? Was it palo alto side or Router/swtich side?

Like I said earlier, can you ditch the HSRP and have BGP peers with both 9500s?

You can read this.  It only applies to Juniper.  Page 8 -

HSRP is only lan side for servers and clients. Layer 3 routed ports from each 9500 to each palo, iBGP full mesh. 


Screen Shot 2019-07-23 at 11.14.58 AM.png

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!