HA active/active dual ISP load balancing

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

HA active/active dual ISP load balancing

L0 Member

Hi all,

I am considering network design that have:

- Dual ISP (public IP /29 for each)

- 2 x PA with active/active HA

- PA connects directly to L2 networks (LAN)

 

Requires:

Load sharing between 2 ISP Internet links

 

Problems:

Is it possible to configure separated nat for each?

How session can failover to remaining PA? Do I need Floating IP for WAN public? 

 

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @nw-rogox ,

 

Active/active does give you the advantage of doubling your NGFW throughput.  However, in a failure scenario the throughput is cut in half which may not be desirable.  The additional complexity of active/active is generally not recommended.  Designs that are too complex tend to not only be a pain to configure as you are feeling now, but they also tend to be a pain to maintain, i.e., new problems may come up in the future.

 

For example, you cannot use a floating IP address in NAT unless you have a common BGP public IP across both ISPs.

 

I do not know of any documents to help you.  I did do a quick Google search and saw a couple videos you may look at.  They both used the switch to connect the dual ISPs to both NGFWs.

 

Sorry!  That is all I have.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Hi @nw-rogox ,

 

I would configure active/passive HA.  It is less complex than active/active.

 

  1. You can create 2 VLANs on your existing switches - one for each ISP.  (As long as you do not create a L3 IP address for the VLANs, the switches will not be accessible from the Internet.)
  2. Then you can connect each ISP to both NGFWs and use active/passive HA.
  3. Enable ECMP with Symmetric Return.
  4. Configure 2 default routes.
  5. Configure NAT normally for each ISP.
  6. You can tune the ECMP hashing if you have weird issues.  https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/ecmp/ecmp-load-balancing-algori...

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Hi Tom,

Much appreciated your support.

As your idea, I need to add 1 physical uplink connection for each PA, but from ISP to PA Firewall, they provide the single RJ45 port via MediaConverter, not switches. However, I am consider to expand the connections as your idea.

 

One thing that, if I use active/active mode, I can leverage the both firewall resources same time, could you give some document or ideas to establish active/active HA with both firewall facing Internet with public IP? 

 

I tried and in ActiveActive mode, it require NAT to the Floating IP, not accept the interface's IP as usual.

 

Cyber Elite
Cyber Elite

Hi @nw-rogox ,

 

Active/active does give you the advantage of doubling your NGFW throughput.  However, in a failure scenario the throughput is cut in half which may not be desirable.  The additional complexity of active/active is generally not recommended.  Designs that are too complex tend to not only be a pain to configure as you are feeling now, but they also tend to be a pain to maintain, i.e., new problems may come up in the future.

 

For example, you cannot use a floating IP address in NAT unless you have a common BGP public IP across both ISPs.

 

I do not know of any documents to help you.  I did do a quick Google search and saw a couple videos you may look at.  They both used the switch to connect the dual ISPs to both NGFWs.

 

Sorry!  That is all I have.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 1540 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!