<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to make upstream connected devices learn that downstream core switches are down in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-make-upstream-connected-devices-learn-that-downstream/m-p/460558#M102088</link>
    <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/207164"&gt;@Sukhmeet&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would address this issue by enabling routing protocol (OSPF or BGP) between Firewalls and Core Switches. If Core Switches are down routes advertised through core switches will be withdrawn. If you can peer with your MPLS provider by BGP you can do more advanced design with conditional route advertisement to inject a route if another route you are tracking is withdrawn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jan 2022 12:58:27 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2022-01-24T12:58:27Z</dc:date>
    <item>
      <title>How to make upstream connected devices learn that downstream core switches are down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-make-upstream-connected-devices-learn-that-downstream/m-p/460463#M102077</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have active passive setup of firewalls in both DC and DR site. The scenario I am trying to work on is, if my downstream connected core switches are down in primary DC, how can make ISP and MPLS connected devices on my upstream learn that all traffic should be routed to DR site firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically, How can we make ISP and MPLS router learn that both core switches are down eventhough the firewalls are UP.?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 05:58:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-make-upstream-connected-devices-learn-that-downstream/m-p/460463#M102077</guid>
      <dc:creator>Sukhmeet</dc:creator>
      <dc:date>2022-01-24T05:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to make upstream connected devices learn that downstream core switches are down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-make-upstream-connected-devices-learn-that-downstream/m-p/460558#M102088</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/207164"&gt;@Sukhmeet&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would address this issue by enabling routing protocol (OSPF or BGP) between Firewalls and Core Switches. If Core Switches are down routes advertised through core switches will be withdrawn. If you can peer with your MPLS provider by BGP you can do more advanced design with conditional route advertisement to inject a route if another route you are tracking is withdrawn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 12:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-make-upstream-connected-devices-learn-that-downstream/m-p/460558#M102088</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-01-24T12:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to make upstream connected devices learn that downstream core switches are down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-make-upstream-connected-devices-learn-that-downstream/m-p/461295#M102153</link>
      <description>&lt;P&gt;Thanks Pavel, yeah it make sense. we will have BGP peering with MPLS router (i will check on conditional route advertisement part) however, we do not have BGP peering with ISP and we are using static route with ECMP enabled on 3 ISP links. Can you tell how can it trigger failover on ISP side when both core switches are down? please note both DCs have same ISP with 3 links and we have VLAN configured which is enabled on primary DC and only when the primary DC ISP link fails secondary DCs ISP Vlans will be enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 04:30:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-make-upstream-connected-devices-learn-that-downstream/m-p/461295#M102153</guid>
      <dc:creator>Sukhmeet</dc:creator>
      <dc:date>2022-01-27T04:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to make upstream connected devices learn that downstream core switches are down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-make-upstream-connected-devices-learn-that-downstream/m-p/461628#M102185</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/207164"&gt;@Sukhmeet&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is hard for me to give further suggestion without knowing all details of your network. Based on what you described that you rely on a static route, my general advice would be following failover mechanism (I apologize for using Cisco terminology).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configure 2x ip sla. One is probing loopback of core switch 1 and second probing loopback of core switch 2.&lt;/P&gt;&lt;P&gt;Configure tracking list with boolean "and operator" to match both ip sla.&lt;/P&gt;&lt;P&gt;Add the tracking object to your static route and redistribute static route to BGP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the above configuration, once both ip sla fail, the tracking object will invalidate static route and BGP will withdraw this route from advertisement. This is the only way I can think of that upstream devices will learn about failure of downstream devices without running routing with them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you mentioned about disabling and enabling Vlan. You can also create an EEM script to take an action based on tracking object to for example shut / no shut vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 23:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-make-upstream-connected-devices-learn-that-downstream/m-p/461628#M102185</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-01-27T23:16:20Z</dc:date>
    </item>
  </channel>
</rss>

