07-26-2017 11:55 AM - edited 03-08-2019 11:29 AM
Hello,
Palo1(Active)(Inside seg) >>>(L2? L3-p2p?)7K1(VPC)
Palo2(Passive)(Inside seg) >>> (L2? L3-p2p?)7K2(VPC)
How should this be done in order to maintain redundancy?
Create a new SVI and VPC for the inside firewall segment, then configure the firewall facing link on each 7K as an access port? This would break the VPC design though, as the the endpoints(Palo Altos) are not capable of VPC or PC technology, right?
What about configuring the interfaces as L3 point to point links? But how would state knowledge of the neighboring Nexus be shared?
Finally, I thought about using a small switch like the 2960CG, port-channeling it up to the 7Ks, then connecting the PAs to the designated inside VLAN.
All support is appreciated.
07-26-2017 01:04 PM
Hi,
I have never deployed PA firewalls but if they function the same as Juniper and Cisco firewalls, you can connect the active firewall to one nexus and passive to the other nexus, put them in one vlan (access) with a /29 or 28 subnet with IP on each device. Nexus-1 one IP, Nexus-2 one IP and firewalls one IP if they are clustered, if not one each.
HTH
04-11-2019 06:08 AM
hi,
i know this was 1 year before but if you need any help in deploying the PA with Cisco network gear, nexus or CAT family. please respond and i will provide you the configurations for VPC or PO's as i have deployed them in both environments.
06-18-2019 12:40 PM
Hi Usman,
Any information you may have on connecting Active/Passive pair of Palos to Nexus5K; would be great!
10-10-2019 02:44 PM
Could you please share the recommended configuration on Nexus side for:
Nexus VPC to PA active/passive in L2 mode.
10-10-2019 05:43 PM
sure why no. we have a multi zone config. I will post the config and a diagram if I can here otherwise send me a buz on usmanalidar@outlook.com and I will share the complete step by step doc with diagram that we have.
10-17-2019 01:07 PM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: