- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-19-2011 04:09 AM
hi,
i have two PA500 appliances am looking to configure them on HA mode , with my current setup i have utilized all 7 ports so one port left for me , as per the documents for HA ( A/A , A/P ) you need 3 or 2 ports to achieve the configuration... so is there a way to achieve HA ( A/P ) with single HA port ? because if not i have to re-setup the appliance to free up two ports for HA :smileygrin:
12-20-2011 07:09 AM
HA consists of two ports, the control (HA1) and the sessions (HA2). If you don't do HA2, all of the clients will have to restart their sessions if the box rolls. May or may not be a big deal.
You might be able to consolidate some of your interfaces with VLANs and trunk interfaces.
12-20-2011 07:09 AM
HA consists of two ports, the control (HA1) and the sessions (HA2). If you don't do HA2, all of the clients will have to restart their sessions if the box rolls. May or may not be a big deal.
You might be able to consolidate some of your interfaces with VLANs and trunk interfaces.
12-20-2011 01:02 PM
We do not support having 1 HA port to handle HA1, HA2, and/or HA3. You need a dedicated Eth port for each HA link. You may want to try the consolidation method as suggested by umphmharding.
Thanks.
12-20-2011 01:41 PM
Have you successfully implemented this at your site or with any customers? I could see this as an option for some of my customers who run PA-500s.
Thanks,
Jared
12-20-2011 01:46 PM
Just running HA1 or the VLAN part?
We ran with just one HA port during testing on our PA-2050s for a day way back on PAN-OS 2.1.5 or 2.1.4. I think there's been a lot of changes since then.
12-20-2011 01:50 PM
Yes, HA is supported for the PA500 and we have customers using it. Just to be clear, you have to use 1 Eth port for each HA link.
12-20-2011 11:03 PM
what if i created a subinterfaces or it requires physical dedicated interfaces , am thinink to create a vlan on the switch for HA sessions create subinterfaces from single interface tag them with vlan id ?
12-21-2011 05:59 AM
The HA interfaces aren't L2 or L3 interfaces, they're special to the PAN. They'll have to be dedicated ports.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!