PA 2020 Active/Passive Cluster on SFP Ports

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA 2020 Active/Passive Cluster on SFP Ports

L1 Bithead

Hi,

I have two  2020 Palo-Alto firewalls with serial no.0004C102807 and 0004C102848. I have to configure them in Active /Passive Cluster. As per the design the two PA Firewalls are not in the same location and they are at different locations and Ethernet Cable (Cat-6) will not be laid between the two Buildings(becoz of distance constraint). However I have a Fibre connectivity between the Two Buildings. Also in my 2020 PA boxes I have two SFP ports. Can I use both of  them for the HA(HA1 and HA2)? I was going through the PA HA configuration Vedio on the website and I saw for HA in 4000 series which is having two Buildin port  as HA1 and HA2. The vedio recommended that HA2 should be a cross over cable. Will the same apply for PA 2020 firewall. If this holds true how can I manage to connect two firewall through UTP as I have only fiber connectivity between the PA firewalls.

Please advice.  

3 REPLIES 3

L6 Presenter

According to https://support.paloaltonetworks.com/index.php?option=com_pan&task=dl_tech_doc&filename=HA-Active-Ac... you should be fine.

The HA1 is used for mgmtplane sync and HA2 (and HA3) is for dataplane sync.

The recommendation is to use the dedicated HA1 port (if available) along with a fiberconverter (if you need fiber between the sites) instead of using builtin sfp due to the fact that when using an in-band port (builtin sfp or other port not labeled HA1) the control messages will be following a less direct route for the controlplane through the dataplane. If the dataplane for some reason fails the HA1 sync (which syncs mgmtplane) might get confused.

Thanks Mikand,

Thnaks for the answer. I aggree that recomended is to use dedicated HA ports for Clustering, but as I said I am running 2020 PA ,which does not have a dedicated ports for HA, so I have to use any ports for HA(HA1& HA2). But I also have a contraints of distance between the two PA as they are placed in two different buildings. so the only choice will be to use the fiber for HA.

Ahh yes if your box doesnt have any dedicated HA interfaces then your only option is to use the dataplance interfaces and in this case I would go for a sfp so the fiber is directly attached to the PAN unit (instead of an external fiberconverter).

  • 2366 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!