Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

PA and VPC

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA and VPC

L4 Transporter

Hi,

pa.png

 

 

Hi, 

Please advise on the above design . Is there any pros and cons ?

 

Thanks

 

 

 

 

6 REPLIES 6

Cyber Elite
Cyber Elite

@simsim,

This is a pretty common configuration for anyone using a Nessus device and the Pro/Con list is really that of vPC in general on that platform. From a PAN perspective a vPC is invisible, and it has the added benefit that you can lose a chassis without an associated firewall failover. 

If you have Nessus hardware, there's really no good reason not to use a vPC instead of just having each node go to one Nessus chassis. 

Hi @BPry 

Thanks for the reply . can you explain what do you mean by "From a PAN perspective a vPC is invisible"

and also "you can lose a chassis without an associated firewall failover"

Second question 

in vpc 101 since there is  all ports are designated both active and passive firewall will receive traffic. (Correct me if I am wrong)

If that yes how a passive firewall handle the traffic

Thanks.

 

Cyber Elite
Cyber Elite

Thanks for the reply . can you explain what do you mean by "From a PAN perspective a vPC is invisible"

You don't do anything special on the firewall when using a virtual PortChannel (vPC) versus a normal PortChannel. It's still just a simple aggregate interface from the firewalls perspective. 

 

and also "you can lose a chassis without an associated firewall failover"

Generally for folks who don't have Nexus switches that have a similar setup, they wouldn't be able to use a vPC and would just use two regular PortChannel configurations. One firewall would be connected to one switch, and the other firewall would be connected to the other. 

The downside of the above configuration is that if you lose the switch your Active firewall is operating off of, you would also trigger a firewall failover. That's not an issue with your vPC configuration, because if one of your Nexus switches goes down the firewall still has the leg to the other switch to operate off of. 

 

Second question 

in vpc 101 since there is  all ports are designated both active and passive firewall will receive traffic. (Correct me if I am wrong)

If that yes how a passive firewall handle the traffic

VPC 100 is going to your passive/secondary firewall and VPC 101 is going to your Active/Primary firewall correct? When your firewall is in a Passive state, it drops all traffic that it receives. So with you using an Aggregate interface, you'll actually want to run LACP and enable LACP pre-negotitation so that your passive firewall sends LACP messages to bring the AE link up to allow faster failover. The passive firewall will drop any actual traffic that it receives, but the LACP messages are enough to keep the vPC up to allow fast failover.

Hi 

@BPry  your help to the community is always awesome. No words to  comment  about your help 

L4 Transporter

Hi 

The third question was about how a passive firewall handles the data traffic, In VPC  the switch will send the traffic in all ports . And the passive firewall drops all traffic. That means the  actual data traffic is ended nowhere ? 

 

Thanks

 

 

@simsim,

This ARTICLE goes into how the pre-negotiation feature actually works for the Passive firewall. The feature effectively allows LACP/LLDP to actually pre-negotiate the connection to allow for faster failovers. 

If you don't enable pre-negotiation, the interface isn't actually accepting any traffic on the passive firewall. So while it's interfaces will show connected, it doesn't respond to ARP or anything like when it's in a passive or non-functional state. 

 

  • 4948 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!