Enter the
Max Ports (number of interfaces) that
are active (1 to 8) in the aggregate group. If the number of interfaces
you assign to the group exceeds the
Max Ports,
the remaining interfaces will be in standby mode. The firewall uses the
LACP Port Priority of each interface you
assign (Step 3) to determine which interfaces are initially active and
to determine the order in which standby interfaces become active upon
failover. If the LACP peers have non-matching port priority values, the
values of the peer with the lower
System Priority
number (default is 32,768; range is 1 to 65,535) will override the other
peer.
(
Optional) For active/passive firewalls only, select
Enable in HA Passive State if you want to
enable LACP pre-negotiation for the passive firewall. LACP
pre-negotiation enables quicker failover to the passive firewall (for
details, see
LACP and LLDP Pre-Negotiation for
Active/Passive HA).
If you select this option, you cannot select
Same System MAC Address for Active-Passive
HA; pre-negotiation requires unique interface MAC
addresses on each HA firewall.
(
Optional) For active/passive firewalls only, select
Same System MAC Address for Active-Passive HA
and specify a single
MAC Address for both HA
firewalls. This option minimizes failover latency if the LACP peers are
virtualized (appearing to the network as a single device). By default,
the option is disabled: each firewall in an HA pair has a unique MAC
address.
If the LACP peers are not
virtualized, use unique MAC addresses to minimize failover
latency.
Click
OK.
Assign interfaces to the aggregate group.
Perform the following steps for each interface (1–8) that will be a member of
the aggregate group.
Select and click the interface name to edit it.
Set the
Interface Type to
Aggregate
Ethernet.
Select the
Aggregate Group you just
defined.
Select the
Link Speed,
Link
Duplex, and
Link State.
As a best practice, set the
same link speed and duplex values for every interface in the group.
For non-matching values, the firewall defaults to the higher speed
and full duplex.
(
Optional) Enter an
LACP Port Priority
(default is 32,768; range is 1 to 65,535) if you enabled LACP for the
aggregate group. If the number of interfaces you assign exceeds the
Max Ports value of the group, the port
priorities determine which interfaces are active or standby. The
interfaces with the lower numeric values (higher priorities) will be
active.
Click
OK.
If the firewalls have an active/active configuration and you are aggregating
HA3 interfaces, enable packet forwarding for the aggregate group.
Select and edit the Packet Forwarding section.
Select the aggregate group you configured for the
HA3
Interface and click
OK.
(
Supported firewalls only) If the interface corresponds to a PoE
(Power over Ethernet) port on the firewall, you can optionally
configure PoE.
Commit your changes.
Verify the aggregate group status.
Select .
Verify that the Link State column displays a green icon for the
aggregate group, indicating that all member interfaces are up. If the
icon is yellow, at least one member is down but not all. If the icon is
red, all members are down.
If you configured LACP, verify that the Features column displays the
LACP enabled icon
for the
aggregate group.
(
PA-7050 and PA-7080 firewalls only) If you have an aggregate
interface group that has interfaces located on different line cards, it is a
best practice to enable the firewall so that it can handle fragmented IP packets
it receives on multiple interfaces of the AE group that are spread over multiple
cards. To do so, use the following CLI operational command with the
hash keyword. (The other two keywords are also shown
for completeness.)
Access the CLI.
Use the following operational CLI command:
set ae-frag
redistribution-policy <
self |
fixed sXdpX |
hash>