PanOS 10.1 Clustering

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PanOS 10.1 Clustering

L2 Linker

Hello,

I am used to configuring clusters on PanOs 8.x and 9.x.
I am now configuring a new infrastructure based on PanOs 10.1.8.

I have seen new options in "High Availability".
1) Under "General" tab what is "Clustering settings" for?
2) what is "Cluster Config" for?

Thanks

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@Charlie80,

To expand on this a bit, what you're used to seeing is just a traditional HA setup. In that regard, you're likely used to seeing Active/Passive and Active/Active from a configuration standpoint. This provides the basis of redundancy to avoid a firewall failure from bringing down your entire environment.

 

With HA Clustering, that process is expanded by quite a bit. This sees the addition of HA4 and HA4-backup interfaces to actually control the clusters, because HA1-3 are already in use if you have an HA pair configured as cluster members. The clustered firewalls all share session state in the event of a failover, but the session owner is the one actually processing and logging the traffic.

The benefit here is that in a distributed environment, you could lose the primary HA pair and traffic would simply failover to another pair in the cluster. You get additional redundancy across your network that maintains session survivability instead of updating routes due to the loss of the pair. 

View solution in original post

2 REPLIES 2

L3 Networker

Hi Charlie

This link will help

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/ha-clustering-overview

 

PCSPI, PCNSCx3,PCNSEx4,, PCSAE,PCDRA

Cyber Elite
Cyber Elite

@Charlie80,

To expand on this a bit, what you're used to seeing is just a traditional HA setup. In that regard, you're likely used to seeing Active/Passive and Active/Active from a configuration standpoint. This provides the basis of redundancy to avoid a firewall failure from bringing down your entire environment.

 

With HA Clustering, that process is expanded by quite a bit. This sees the addition of HA4 and HA4-backup interfaces to actually control the clusters, because HA1-3 are already in use if you have an HA pair configured as cluster members. The clustered firewalls all share session state in the event of a failover, but the session owner is the one actually processing and logging the traffic.

The benefit here is that in a distributed environment, you could lose the primary HA pair and traffic would simply failover to another pair in the cluster. You get additional redundancy across your network that maintains session survivability instead of updating routes due to the loss of the pair. 

  • 1 accepted solution
  • 1325 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!