- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-09-2025 01:36 PM
Currently have a couple pairs of Palos (internal and external), with an HA pair over at a remote location. These 2 sites at connected via redundant DWDM devices (SmartOptics to be precise). Currently the HA links are just connected to a core switch, then passes to the other site over a stretched VLAN. Just seeing if it'd be wise to just move these over via the DWDM instead of via a L2/3 switch. Open to comments on pros and cons of both
08-11-2025 02:29 AM
@FrankRocks wrote:Currently have a couple pairs of Palos (internal and external), with an HA pair over at a remote location. These 2 sites at connected via redundant DWDM devices (SmartOptics to be precise). Currently the HA links are just connected to a core switch, then passes to the other site over a stretched VLAN. Just seeing if it'd be wise to just move these over via the DWDM instead of via a L2/3 switch. Open to comments on pros and cons of both
Hello,
Both methods of connecting your Palo Alto HA links have pros and cons. Using a stretched VLAN over your core switches, as you are now, offers a simple and potentially cost-effective solution if you already have the infrastructure. It allows for Layer 2 failover, which is a key requirement for the HA2 (data) link in an active/passive configuration. However, this approach can introduce complexity and a single point of failure if your core switches or the stretched VLAN itself experiences an issue. Moving the HA links directly to the DWDM devices, on the other hand, provides a more direct and dedicated path, which could lead to lower latency and a more robust connection for the critical HA communication. This can also remove the core switches from the HA path, potentially simplifying troubleshooting and reducing the blast radius of a network event. The main drawback might be the cost and complexity of the DWDM configuration itself and ensuring the HA links are properly provisioned and isolated on that platform. The choice depends on your specific needs for latency, budget, and network resilience.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!