LACP from Palo 3020 Active - Passive to Cisco switch

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

LACP from Palo 3020 Active - Passive to Cisco switch

L1 Bithead

Hi All

After some help from the Guru's.

I am trying to configure LACP between PA 3020 Active / Passive and cisco switch.

I have created the AE group interface Inside with the ip address.

I have added 2 interfaces to the AE Group on each FW.

 

I have created a portchannel on the Cisco switch and put the 2 ports from the Active Palo and 2 ports from the Passive Palo into the same channel-group.

 

The Active FW is all good and working fine, the Passive FW is connected but the Port channel is suspended on the cisco end for the Passive FW conected ports.

 

Is this correct?

I am worried if the Active FW fails over and the Passive goes active its ports are suspended so wont come online.

 

Any advise greatly appreciated 

 

Simon

1 ACCEPTED SOLUTION

Accepted Solutions

L7 Applicator

I did something similar to this in the lab.  You need 2 port channels on the Cisco switch.  One for the Active firewall, and the other for the Passive firewall.  

 

If you set "Passive Link State" to Auto in the High Availability configuration, then you should be able to enable pre-negotiation for the passive firewall.  At this point, the Cisco switch should show both port-channels up and ready to go - reducing failover time.  

 

 

View solution in original post

7 REPLIES 7

Cyber Elite
Cyber Elite

Hi @Simon.Cardman

 

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/configure-active-p...

 

Did you configure your HA pair according to the mentionned documentation? Specially Step 12 and 14?

 

Regards,

Remo

Hi Remo

Yes, just double checked and it is the same.

I wonder whether this is the norm, I am new to Palo so not done this before.

All interfaces are identical.

Hopefully someone has done this before and will advise.

 

thanks

 

Simon

What PAN-OS Version are you using?

7.1.4-h2

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!