<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can Palo notice and react to a flapping Internet link? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-palo-notice-and-react-to-a-flapping-internet-link/m-p/575342#M2554</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have simple setup, when firewall is connected over physical interface to a L2 switch, while L2 switch is connected to 2 CPEs of different ISPs. Obviously, next hop for our firewall going out is an interface of the CPE. We are tracking default routes for both ISP using route monitoring feature.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, that does not seem to cover a situation when you have a flapping Internet link between L2 switch and any of CPE. Yes, you can go aggressive, add that CPE address in default route monitoring and have pings sent every second, so at the minimum if for 3 seconds there's no response - it will remove default route, but such thing also increase the possibility of false-positives as we also monitor some external destinations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any more elegant way of catching flapping internet link?&lt;/P&gt;</description>
    <pubDate>Thu, 01 Feb 2024 14:59:13 GMT</pubDate>
    <dc:creator>Andreikin</dc:creator>
    <dc:date>2024-02-01T14:59:13Z</dc:date>
    <item>
      <title>Can Palo notice and react to a flapping Internet link?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-palo-notice-and-react-to-a-flapping-internet-link/m-p/575342#M2554</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have simple setup, when firewall is connected over physical interface to a L2 switch, while L2 switch is connected to 2 CPEs of different ISPs. Obviously, next hop for our firewall going out is an interface of the CPE. We are tracking default routes for both ISP using route monitoring feature.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, that does not seem to cover a situation when you have a flapping Internet link between L2 switch and any of CPE. Yes, you can go aggressive, add that CPE address in default route monitoring and have pings sent every second, so at the minimum if for 3 seconds there's no response - it will remove default route, but such thing also increase the possibility of false-positives as we also monitor some external destinations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any more elegant way of catching flapping internet link?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 14:59:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-palo-notice-and-react-to-a-flapping-internet-link/m-p/575342#M2554</guid>
      <dc:creator>Andreikin</dc:creator>
      <dc:date>2024-02-01T14:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can Palo notice and react to a flapping Internet link?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-palo-notice-and-react-to-a-flapping-internet-link/m-p/575503#M2564</link>
      <description>&lt;P&gt;if this helps: if you set up path monitor in your VR, the path will always be sourced from the source IP you configure, so if you use both ISPs to monitor the same destination and one ISP goes down, only one probe will fail&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if the remote IP goes down, you do get a false negative (which can be fixed by setting different destination IP or something that's been set up redundantly)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if one ISP is very prone to extended periods of flapping, you could create an HA path monitor that fails over when such case is detected, and only connect the reliable ISP to the second firewall&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 13:21:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-palo-notice-and-react-to-a-flapping-internet-link/m-p/575503#M2564</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-02-02T13:21:55Z</dc:date>
    </item>
  </channel>
</rss>

