<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Routing the return traffic for on Prem network through Expressroute in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/routing-the-return-traffic-for-on-prem-network-through/m-p/359438#M1040</link>
    <description>&lt;P&gt;We have 2 Palo alto firewalls in Azure using the so called 'load balancer sandwich.'&amp;nbsp; In addition we have a Microsoft ExpressRoute for connectivity to our on prem network.&amp;nbsp; &amp;nbsp;Currently our Expressroute traffic goes around the Palos but the intent is to have the expressroute traffic also go through the Palos.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if I create a UDR for one of the Subnets to the internal loadbalancer which then routes to either one of the 2 firewalls, I see the traffic going to our expressRoute on prem network fine.&amp;nbsp; But if I initiate the traffic from our datacenter to Azure, the traffic doesn't go through the firewall.&amp;nbsp; &amp;nbsp;I've read that I need to have a udr on the gateway subnet in Azure pointing to the trust interfaces (or in our case the internal load balancer).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the Palos point of view the expressroute is on the Untrust.&amp;nbsp; and so when I put a udr on the gateway subnet I'm having the return traffic go to the trust interfaces.&amp;nbsp; I've tried to see if i can force the Palos to route the expressroute traffic through the trust interface by creating static routes to either our internal load balancer or the azure gateway.&amp;nbsp; But each configuration breaks connectivity.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is do I need the expressroute traffic to be going out the trust and not the untrust interfaces?&amp;nbsp; &amp;nbsp;I'm a little confused.&amp;nbsp; hope someone can shed some light.&amp;nbsp; thanks so much!&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2020 22:01:10 GMT</pubDate>
    <dc:creator>nleslie1970</dc:creator>
    <dc:date>2020-10-28T22:01:10Z</dc:date>
    <item>
      <title>Routing the return traffic for on Prem network through Expressroute</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/routing-the-return-traffic-for-on-prem-network-through/m-p/359438#M1040</link>
      <description>&lt;P&gt;We have 2 Palo alto firewalls in Azure using the so called 'load balancer sandwich.'&amp;nbsp; In addition we have a Microsoft ExpressRoute for connectivity to our on prem network.&amp;nbsp; &amp;nbsp;Currently our Expressroute traffic goes around the Palos but the intent is to have the expressroute traffic also go through the Palos.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if I create a UDR for one of the Subnets to the internal loadbalancer which then routes to either one of the 2 firewalls, I see the traffic going to our expressRoute on prem network fine.&amp;nbsp; But if I initiate the traffic from our datacenter to Azure, the traffic doesn't go through the firewall.&amp;nbsp; &amp;nbsp;I've read that I need to have a udr on the gateway subnet in Azure pointing to the trust interfaces (or in our case the internal load balancer).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the Palos point of view the expressroute is on the Untrust.&amp;nbsp; and so when I put a udr on the gateway subnet I'm having the return traffic go to the trust interfaces.&amp;nbsp; I've tried to see if i can force the Palos to route the expressroute traffic through the trust interface by creating static routes to either our internal load balancer or the azure gateway.&amp;nbsp; But each configuration breaks connectivity.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is do I need the expressroute traffic to be going out the trust and not the untrust interfaces?&amp;nbsp; &amp;nbsp;I'm a little confused.&amp;nbsp; hope someone can shed some light.&amp;nbsp; thanks so much!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 22:01:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/routing-the-return-traffic-for-on-prem-network-through/m-p/359438#M1040</guid>
      <dc:creator>nleslie1970</dc:creator>
      <dc:date>2020-10-28T22:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Routing the return traffic for on Prem network through Expressroute</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/routing-the-return-traffic-for-on-prem-network-through/m-p/359731#M1041</link>
      <description>&lt;P&gt;I got it working.&amp;nbsp; I created a static route on my Trust-vr for my On prem network - 10.0.0.0/8 that routes to my load balancer on my trust side.&amp;nbsp; &amp;nbsp;Then on the gateway subnet i created a route for my Azure subnet going to my loadbalancer as well and now traffic from my express route is going through my firewall!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 19:16:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/routing-the-return-traffic-for-on-prem-network-through/m-p/359731#M1041</guid>
      <dc:creator>nleslie1970</dc:creator>
      <dc:date>2020-10-29T19:16:13Z</dc:date>
    </item>
  </channel>
</rss>

