High Availability Latency / Bandwidth Requirements

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

High Availability Latency / Bandwidth Requirements

L2 Linker

What are the Latency / Bandwidth Requirements for HA1 interfaces links between 2 HA members?

 

I saw a similar discussion here, but there is no actual answer in it

https://live.paloaltonetworks.com/t5/general-topics/high-availability-bandwidth-latency-requirements...

 

There is another related article: Next-Generation Firewall :HA Timers, but the timers here are mostly intervals rather than Latency.

https://docs.paloaltonetworks.com/ngfw/administration/high-availability/ha-timers

 

 

So I need to order a circuit (link) between 1 firewalls with Geo-cluster, and I need to know the requirements for it.

 

Thx

4 REPLIES 4

Community Team Member

Hi @ET ,

 

There are no officially published latency or bandwidth requirements for HA1. The real requirement is simply that the circuit is stable, low-loss, and not congested. 

 

For real numbers, you'll have to capture the HA1 traffic between the peers or review interface counters/stats on an intermediate switch. 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L6 Presenter

@ET -- What is your datacenter design / strategy?  What is your desired firewall architecture/design?  You shouldn't need a dedicated circuit just for HA. Like @JayGolf  mentioned there isn't any specific guidance.  It's more about criteria & and thresholds and making sure your settings in HA are aligned with what the circuit is delivering.

 

These settings can/should be tuned to the circuit the communication traverses. 

 

Brandon_Wertz_1-1764088088483.png

 

 

Brandon_Wertz_0-1764087949653.png

 

Cyber Elite
Cyber Elite

latency for HA1 is not as critical as HA2 or HA3 since you're not synchronizing live session data.

The most important data sent over HA1 is the user-ID table and DHCP leases which in most cases will not cause immense havoc even if there is high latency

If you're worried about your FIB, you could consider running Active/Active without routing sync 

 

https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchroniz...

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

These setting are mostly (if not all) about intervals between sampling. It's not related to latency to my understanding

  • 143 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!