<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure multiple public front ends on load balancer in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-multiple-public-front-ends-on-load-balancer/m-p/254009#M558</link>
    <description>&lt;P&gt;Rather than different interfaces, I would recommend using Port Translation or secondary IPs on one Untrust interface to glue the inbound traffic to the destination nat.&amp;nbsp; As you encountered, multiple interfaces will result in complex routing that is accomplished through VR mapping internal and external interfaces together or putting all Untrust Interfaces in the same zome to over come the asymmetry with multiple 0/0 outbound routes for each interface.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 16 Mar 2019 03:59:22 GMT</pubDate>
    <dc:creator>jmeurer</dc:creator>
    <dc:date>2019-03-16T03:59:22Z</dc:date>
    <item>
      <title>Azure multiple public front ends on load balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-multiple-public-front-ends-on-load-balancer/m-p/254008#M557</link>
      <description>&lt;P&gt;Using multiple front end IPs to split my internet facing applications. Seemed to solve the health probe issue with splitting static &lt;SPAN&gt;168.63.129.16/32&amp;nbsp;&lt;/SPAN&gt;azure routes between virtual routers, but inbound traffic doesn't seem to know where to go. Single public application worked no problem, as soon as second front end IP is added, the VM series stops routing. Intend to add second VMseries 300 in parallel when PoC is cleared through single.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 Front end public IPs&lt;/P&gt;&lt;P&gt;2 Untrust interfaces in 2 Separate Backend pools&lt;/P&gt;&lt;P&gt;2 Health probes to untrust interfaces&lt;/P&gt;&lt;P&gt;2 Load balancing rules with client IP persistance&lt;/P&gt;&lt;P&gt;NAT 1 from untrust to untrust interface 1 translated to app A (private IP)&lt;/P&gt;&lt;P&gt;NAT 2 from untrust to untrust interface 2 translated to app B (Private IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems like routing is unsure of where to go outbound with the 2 untrust Interfaces. Static routes and virtual routers are split between traffic destined for untrust interfaces based off source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2019 02:53:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-multiple-public-front-ends-on-load-balancer/m-p/254008#M557</guid>
      <dc:creator>joeritt</dc:creator>
      <dc:date>2019-03-16T02:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Azure multiple public front ends on load balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-multiple-public-front-ends-on-load-balancer/m-p/254009#M558</link>
      <description>&lt;P&gt;Rather than different interfaces, I would recommend using Port Translation or secondary IPs on one Untrust interface to glue the inbound traffic to the destination nat.&amp;nbsp; As you encountered, multiple interfaces will result in complex routing that is accomplished through VR mapping internal and external interfaces together or putting all Untrust Interfaces in the same zome to over come the asymmetry with multiple 0/0 outbound routes for each interface.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2019 03:59:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-multiple-public-front-ends-on-load-balancer/m-p/254009#M558</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-03-16T03:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: Azure multiple public front ends on load balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-multiple-public-front-ends-on-load-balancer/m-p/516768#M1682</link>
      <description>&lt;P&gt;Why not the same backend pool but different ports?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 14:40:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-multiple-public-front-ends-on-load-balancer/m-p/516768#M1682</guid>
      <dc:creator>slashBack</dc:creator>
      <dc:date>2022-10-04T14:40:04Z</dc:date>
    </item>
  </channel>
</rss>

