Two locations Two pairs of 5050s Have a configuration wtih two sets of aggregate ports One set of VLANs that are local/native to the location the PAN assigned to the first set of aggregate ports - these are intended to be up at all times. The other set of VLANs are assigned to the other data center but are stretched across the WAN backhaul to the other location - these interfaces will only be up when the other data center is down (either during a failure scenario or during a DR test) Unfortunately when the physical interfaces are down (either through the Palo Alto configuration or through the Port Channel being turned down on the switch), the aggregate sub interfaces remain active and the routes to those subnets remain active on the local firewall. If a single interface is configured with a subnet and virtual router and is down, then the routes do not appear in the routing table. In this configuration the routes remain in place even though the physical interfaces associated with the aggregate interface are down. Is this functioning by design or is this an issue that we should open a case for? If it is by design, is there a way to effectively down the aggreate interface (and sub interfaces) so that the routing goes into a disabled state? Thanks James
... View more