<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I create a dual globalprotect gateway on my firewall with ISP failover? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-i-create-a-dual-globalprotect-gateway-on-my-firewall-with/m-p/375118#M713</link>
    <description>&lt;P&gt;We have 2 ISP on our PA-850. We have 1 VR with both ISP set as the default route for primary and backup internet (different metrics) with a static route monitoring failover process. I have configured ISP1 for GP-gateway1 and and ISP2 for GP-gateway2. In this case, I wasn't able to connect to the second GP-gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried configuring 2 VRs, ISP1 as default route for VR1 and ISP2 as default route for VR2. This way, I was able to connect to both GP gateway simultaneously. How do I do the failover in this scenario? What I want to achieve is, all traffic coming in from internal, ipsec and GlobalProtect regardless of the VR, will forward it on ISP1. If ISP1 will go down, all traffic will shift to ISP2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Found this article&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClU8CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClU8CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but it doesnt say anything about failover.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this doable by using policy based forwarding? if so, how do I configure it on the VRs including the ipsecs and GP tunnels.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Dec 2020 07:15:14 GMT</pubDate>
    <dc:creator>Gabriel.Buldiman</dc:creator>
    <dc:date>2020-12-18T07:15:14Z</dc:date>
    <item>
      <title>Can I create a dual globalprotect gateway on my firewall with ISP failover?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-i-create-a-dual-globalprotect-gateway-on-my-firewall-with/m-p/375118#M713</link>
      <description>&lt;P&gt;We have 2 ISP on our PA-850. We have 1 VR with both ISP set as the default route for primary and backup internet (different metrics) with a static route monitoring failover process. I have configured ISP1 for GP-gateway1 and and ISP2 for GP-gateway2. In this case, I wasn't able to connect to the second GP-gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried configuring 2 VRs, ISP1 as default route for VR1 and ISP2 as default route for VR2. This way, I was able to connect to both GP gateway simultaneously. How do I do the failover in this scenario? What I want to achieve is, all traffic coming in from internal, ipsec and GlobalProtect regardless of the VR, will forward it on ISP1. If ISP1 will go down, all traffic will shift to ISP2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Found this article&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClU8CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClU8CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but it doesnt say anything about failover.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this doable by using policy based forwarding? if so, how do I configure it on the VRs including the ipsecs and GP tunnels.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 07:15:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-i-create-a-dual-globalprotect-gateway-on-my-firewall-with/m-p/375118#M713</guid>
      <dc:creator>Gabriel.Buldiman</dc:creator>
      <dc:date>2020-12-18T07:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create a dual globalprotect gateway on my firewall with ISP failover?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-i-create-a-dual-globalprotect-gateway-on-my-firewall-with/m-p/375197#M715</link>
      <description>&lt;P&gt;Hey Gabriel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would test using path-monitoring setup similar to the below and create the same for the second route on the SAME VR:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sarc845_1-1608292418378.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29197iF475A61E29723DDB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Sarc845_1-1608292418378.png" alt="Sarc845_1-1608292418378.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the ISP Peer becomes unreachable via ICMP it will remove it from the routing table and fall back to the failover default route:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sarc845_0-1608293021250.png" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29200i27FC7B0CC6899199/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Sarc845_0-1608293021250.png" alt="Sarc845_0-1608293021250.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then create the same setup for the second VR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: Remember to set a higher metric for the failover route and note the failover route routes to the next VR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 12:01:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-i-create-a-dual-globalprotect-gateway-on-my-firewall-with/m-p/375197#M715</guid>
      <dc:creator>Sarc845</dc:creator>
      <dc:date>2020-12-18T12:01:20Z</dc:date>
    </item>
  </channel>
</rss>

