PA 3260 and using non dedicated as HA1 interface

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PA 3260 and using non dedicated as HA1 interface

Cyber Elite
Cyber Elite

We have 2 PA 3260  across Data Centres.

We tried to use Eth1/13 as HA1 port but under ha1 interfaces it does not show option to choose  eth1/13.

 

IS this by design that HA1 interface to be dedicated?

for now we used management as ha1 interface.

 

is this good to use management interface as ha1?

 

Regards

Mike

MP

Help the community: Like helpful comments and mark solutions.
8 REPLIES 8

L7 Applicator

Did you configure eth1/13 as HA interface prior to selecting it in the HA config?

 

(I normally use the mgmt port as HA1 backup port in addition to either one of the dedicated or a DP interfaces)

Yes i config eth1/13 as HA interface.

MP

Help the community: Like helpful comments and mark solutions.

L6 Presenter

@MP18 wrote:

We have 2 PA 3260  across Data Centres.

We tried to use Eth1/13 as HA1 port but under ha1 interfaces it does not show option to choose  eth1/13.

 

IS this by design that HA1 interface to be dedicated?

for now we used management as ha1 interface.

 

is this good to use management interface as ha1?

 

Regards

Mike


Why can't you use the HA1 port even if the firewalls are across DCs?  (I'm guessing you're needing a fiber connection?)  

 

I've got a 5220 pair spreed across 2 DCs that are 800+ miles apart using HA1 in a switched environment w/o issue.

Yes it is a fiber connection connection between our Data centres for HA!

MP

Help the community: Like helpful comments and mark solutions.


@MP18 wrote:

Yes it is a fiber connection connection between our Data centres for HA!


Can you land this fiber into a switch?  Then plug copper from the switch into HA1?

@MP18 

The 3200 series, much like the 5200 series, will only allow ha1-a, ha1-b or management to be utilized for HA1. The 5200 series has the advantage of being able to utilize the aux-1 and aux-2 ports as HA1 interfaces. 

In this type of situation, I would recommend doing exactly what @Brandon_Wertz is saying and simply running HA1 through a switch and passing it to the PA as a copper handoff; this works perfectly fine and I'd recommend it before setting HA1 to the management interface. 

We are also checking with our PA SE if this is due to hardware or software.

Will keep everyone updated once we hear  from him

 

MP

Help the community: Like helpful comments and mark solutions.

Hi,
I don't know if this is a new feature not available back in 2020, but we could run HA1a and HA1b direct FW to FW over fiber on a PA-3260 without issue. (using ethx.x interfaces)
Hope this could help if you want to avoid having a switch in the middle.

Regards.

  • 5892 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!