set deviceconfig setting session tcp-reject-non-syn no I alway use this command in vwire mode, for me PAN should implement it as default In your case you used A/A but wouldnt it be sufficient to use two (or more) standalone PA-boxes aswell? Using two different separate boxes managed by Panorama could be a solution as well, but in the specific project vwire is only a part of the entire solution. I dedicated also ports for ly3 configuration and HA have to be configured. A/P was not the best choice so I decided to set A/A. Session sync is not an issue due to load-balance algorithm and the way how HA is porformed. In case of failure of one device (or cable) sessions are already duplicated from active-primary to active-secondary (and reverse) via HA2 and HA3 links, The issue is on log sparse on two different boxes but using panorama as global collector even this is not a major problem. Also HA license are less expensive than 2 separate ones. The docs you linked are about core switches similar to Cisco Nexus family, low latency hig performaces, but the configuration with multiple PAs in vwire absorbing etherchnnel single links, is usable anyhow. Some months ago I found an interesting document,maybe a partner one I have to check, talking about PAN in datacenter, as soon as I found I'll post here.
... View more