Hello, I absolutely understand the concerns you have put forth in this discussion. Managing a pair of firewalls in active/active configuration through a panorama is very tricky...:) Coming back to the point you have made with assigning ip addresses to physical ports, there are couple of things to consider : - If the interface ip addresses are pushed from the panorama using network templates, it is good to have two different templates. One for active-primary and another for active Secondary. - Another way to implement it would be to configured the interfaces with ip-addresses locally on the firewall rather then pushing it from the panorama as a template. Hope this helps Thanks
... View more