I've deployed a few Azure HA PANOS 9.0.1 pairs. They work as expected, I've done many rounds of testing. It is true, the Azure portion of the failover can take 2 - 3 minutes for the floating IPs to move; however, the design is much more straight forward than the LB sandwich in Azure. Also, I've tested VPN/IPSec tunnels failover smoothly with the HA deployment, can't say that's even an option with the Azure LB sandwich without Azure Function/Automation updating a UDR after the pri fails. I'm curious about the previous poster's passive node not working after 20 minutes... was that issue resolved?
... View more