Do I need to deploy a switch between 2xPA firewall (Active-Passive) and 1xJuniper MX router ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Do I need to deploy a switch between 2xPA firewall (Active-Passive) and 1xJuniper MX router ?

L1 Bithead

Do I need to deploy a switch between PA firewall (AP) and a Juniper Router in order to have an aggregate ethernet interface (AE) connected? Please refer to the diagram attached.

 

The setup is below:

 

PA-1 (A)-------------PA-2 (P)

|                              |

|                              |

|          LACP           |

 

Juniper router

 

 

5 REPLIES 5

L1 Bithead

Here is the diagram.image.png

Cyber Elite
Cyber Elite

Hello,

I cannot say for sure, but shouldnt have to. The Juniper will just see the connection to the passive PAN as down.

Regards,

Thanks for your reply Otakar, from PA AP, it can keep track of the ae0 link, in case the ae0 (1xchild interface only) is not response ping or down, the Active PA can trigger a failover to the passive one. 

However, I might think about if the traffic will go through ae1 link since the link is up on Passive PA and it will blackhole the traffice.

Or you think the traffic won't go through the ae1 between MX and PA-passive FW?  

Cyber Elite
Cyber Elite

Device > High Availability > General

 

If it is Shutdown then Juniper sees AE1 as down.

If it is set to Auto then AE1 link is up but passive Palo is not responding to ARP requests so if Juniper don't have any ARP entries pointing to AE1 it should not send any traffic towards it.

 

Benefit with auto is that you can have LACP pre-negotiated on passive Palo and failover takes less time.

 

Raido_Rattameister_0-1705585500104.png

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

L1 Bithead

Thanks chaps!

  • 1188 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!