cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Cyber Elite
Cyber Elite

Yes you can set up 2x PA-440 in HA.

If you configure management interface to be used as HA1 then you need to configure one of dataplane interfaces to be HA2 to syncronize sessions over. Without HA2 all sessions need to be re-initiated when firewalls fail over.

 

If you have more dataplane ports available you can have HA1 backup.

HA1 backup eliminates split brain situation.

If you happen to disconnect mgmt interface on one of firewalls and they don't see each other any more over HA1 link then both become active at the same time and this is bad 🙂 
HA1 backup helps in this scenario.

 

HA2 backup gives backup link for session sync but this is most likely overkill in small setup.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

Who rated this post