Hi @itserviceHEWA @itserviceHEWAwrote: So here is my question: For us, it is critical that both HA members will be active (split brain), because firewall A has to handle traffic from company A and firewall B hast to handle traffic for company B until the HA links recover. Will this work like I suggest? Yes, this will work as you suggested. As long both firewalls know nothing about the other they both assume that they have to be "active" and handle traffic. @itserviceHEWAwrote: And the next question: When recovering from split brain (wich we need to force), which device will sync its log entries to the other or are both logentries will be brought togehter (wich would be the perfect thing). The logs aren't synched at all. For such a situation you would need addfitional servers to store the logs. An option would be panorama. During the split-brain you only have the logs from one firewall (in case of one panorama), but after the split-brain the firewall that lost connection to panorama will send all the missing logs to panorama. Syslog servers are also an option but then you would need at least 2 syslog servers and something that has the intelligence to keep then in sync after the split-brain. So probably panorama is the easier solution. @itserviceHEWAwrote: Are there any other concerns about recovering from split brain? Is the split datapath option in HA needed, although it is pointed out only to use in A/A deployments. (The option would be available in A/P deployment) In your situation you don't need to worry about this option. As I wrote, as long as the firewalls don't see each other both will automatically become active. But when recovering from solit-brain some connections might need to be reestablished - probably the ones on the firewall that becomes passive after the split-brain. Regards, Remo
... View more