PAN does strongly prefer active/passive. But asymmetrical routing is not the only case where active/active is required.
Active/active is required is if your infratructure requires communication be permitted between devices connected to the secondary firewall at all times. With PAN Active/Passive the secondary (passive) node has interfaces connected, link is up but no traffic will pass until the device becomes active.
This is great for preventing layer 2 loops when the active and passive device are simply an alternate path for the same traffic.
But if you network design is fully active/active and therefore there is traffic such as bgp, vrrp, or other protocols that need to communicate on secondary links at all times, you must have the PAN cluster setup as active/active.
And if the network design is fully active/active where the traffic load is distributed across both paths, then active/active is also required.
... View more