How to use Seprate IPs on WAN interface of 2 Paloalto Firewall.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

How to use Seprate IPs on WAN interface of 2 Paloalto Firewall.

L1 Bithead

Im new in PaloAlto and configuring HA Active/Passive Mode with seprate IPs on WAN Interface in both Firewall, every thing is working fine but when Active Firewall 1 Syncronized with Firewall 2 its change the Firewall 2 WAN IP with Firewall 1 WAN IPs in that case my all routing to oustside is Block in Firewall 2 because it has different route outside than Firewall 1.

 

Any one kinldy can guide me how i can design PaloAlto firewall WAN interfaces using Active/Passive Mode in case of Single ISP for both firewall or Dual ISP for better redundancy.

 

aamirns_0-1653313000551.png

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hello,

in Active/Passive mode, the WAN IP's will be the same on the active firewall. Lets say Active firewall has IP 1.1.1.1, if there is a failover event the passive(no active) firewall will have its WAN IP of 1.1.1.1. There are only a few things that do not sync in HA, they are all on the Device tab. 

Here are some links for reference:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIbCAK

 

Regards,

View solution in original post

7 REPLIES 7

L5 Sessionator

Why do A/P HA devices need different routes?

If we have two internet connection from same ISP or from Different ISP. for redundancy.

You need the redundant circuit connected to both PAs, just like the primary.  Interface configuration and routes sync between active and passive nodes. Link - What doesn't sync between active/passive 

Then you'll need to choose how to utilize both circuits during normal operation and during failover.

L1 Bithead

If you can see my visio i have only 2 internet connection one for each firewall either from Same ISP or Dual ISP.  every thing is working fine so far with Left side Firewall is in Active mode, but in case of failover when right side Firewall will become Acitve i want my traffic should go through its WAN IP. Problem is this HA syncrozised changed the WAN IP to same for both firewall. how i can overcome this situation WAN IP should be identical for both firewalls not same

Cyber Elite
Cyber Elite

Hello,

in Active/Passive mode, the WAN IP's will be the same on the active firewall. Lets say Active firewall has IP 1.1.1.1, if there is a failover event the passive(no active) firewall will have its WAN IP of 1.1.1.1. There are only a few things that do not sync in HA, they are all on the Device tab. 

Here are some links for reference:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIbCAK

 

Regards,

L1 Bithead

Is not possible to use any switches? In this way, you can connect the ISP to both FW (on the same port) without any problem. If you want to use another ISP for redundancy, use another port for both fw too.

Cyber Elite
Cyber Elite

Hello,

You sure can, just need to make sure that the configuration and routing is correct. However with regards to HA, in active/passive mode, only 1 firewall is Active so the other one has its ports shut down.

Regards,

  • 1 accepted solution
  • 3132 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!