HA3 Link Connectivity Through a Layer 2 Switch?

HA3 Link Connectivity Through a Layer 2 Switch?

27102
Created On 09/25/18 17:51 PM - Last Modified 11/10/22 03:46 AM


Symptom


Can a Layer2 switch be used between Firewalls for HA3 connectivity?

Environment


  • Palo Alto 800, 3200 and PA-5200 Series firewalls
  • Supported PAN-OS.


Resolution


  1. Yes, the HA3 interface on an HA (High Availability) Active - Active setup can be connected through a Layer 2 switch between the HA pair.
  2. A switch supporting jumbo frame is required.
  3. Jumbo frame support does not explicitly need to be enabled on the Palo Alto Networks firewall, as the HA3 interface supports jumbo frames independently of the system configuration.

Note:

  • On PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls, the dedicated HSCI ports support the HA3 link.
  • The traffic carried on the HSCI ports is raw Layer 1 traffic, which is not routable or switchable. Therefore, you must connect the HSCI ports directly to each other 
  • Refer HA Links and Backup Links  and  HA Ports on Palo Alto Networks Firewalls for detailed information.

     

     



    Additional Information


    In a High Availability (HA) configuration, HA3 uses L2 between the firewalls. The firewall will add 18 bytes to the frame. Without support for jumbo frames, network traffic with frame size over 1514 may get dropped by the switch and the traffic will fail.

    The 18 bytes that make up the total extra overhead consist of:

    • 6 bytes for the dest mac of the peer HA3 port
    • 6 bytes for the src mac of HA3 port
    • 2 bytes for the protocol number
    • 4 bytes for an essential private field


    Actions
    • Print
    • Copy Link

      https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKd&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

    Choose Language