- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
12-25-2023 02:01 PM
Can we confgure the Shared IP in the WAN side in HA Active/Active?
Because I read in the PAN OS Admin guide two things:
Page 410: As illustrated in the floating IP address scenario, the firewall supports a shared IP address
for ARP load-sharing only on the LAN side of the firewall; the shared IP address cannot be
on the WAN side.
In the same Guide, page 449:
Use Case: Configure Active/Active HA for ARP Load-Sharing with Destination NAT
This Layer 3 interface example uses NAT in Active/Active HA Mode and ARP Load-Sharing
with destination NAT. Both HA firewalls respond to an ARP request for the destination NAT
address with the ingress interface MAC address. Destination NAT translates the public, shared
IP address (in this example, 10.1.1.200) to the private IP address of the server (in this example,
192.168.2.200).
The configuration of this use case shown that on the WAN Side, a Shared IP or a Virtual Address is configured.
My question, is there any contradiction or something I misunderstood?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!