Hi, Thank you for your answer, but either I'm not understanding your answer or I didn't make myself clear. To give an example, Check Point firewalls allow you to set up cluster members to share an IP address, but only the active member receives and processes traffic to it. This is useful for next-hop addresses-set your downstream router to use the virtual ip address, and whichever gateway is the active member receives traffic to that address. When the primary gateway fails the secondary address takes over the virtuall ip address and begins to receive and process traffic destined to that address. I cannot find a way to create this 'virtual' address in Palo Alto, and as such I don't understand how you would set a default gateway to an address if a HA cluster doesn't have a "floating" IP address. Thank you again
... View more