<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DUAL ISP and PFB with single or multiple Virtual Routers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-pfb-with-single-or-multiple-virtual-routers/m-p/496236#M105153</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello Palo Alto Community! I am reaching out because I am stuck and a bit confused about what I've seen online when it comes to configuring dual ISP and PFB (which that part I understand) but when configuring the Virtual Routers section. Some only create a single VR with both ISP and their next hops and others create their ISP each VRs and then there is a return internal network and their next hop is a VR. Here's what I have done so far:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have two ISPs (Comcast &amp;amp; AT&amp;amp;T) and would like for both of these ISP links to be routing traffic. I have read and reviewed a few Palo Alto-supported documentation &amp;amp; blogs from other sites. I've configured a few things on our firewall but I am not 100% clear on a few configurations that I have done to make sure it will work properly before going live.&lt;BR /&gt;&lt;BR /&gt;Here's what I've done so far:&lt;BR /&gt;&lt;BR /&gt;• Interfaces:&lt;BR /&gt;o Eth. 1/1 (native VLAN) and along subinterfaces for LAN&lt;BR /&gt;o Eth. 1/10 for AT&amp;amp;T ISP Link&lt;BR /&gt;o Eth. 1/12 for Comcast ISP Link&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;• Zones:&lt;BR /&gt;o Created ISP_ATT &amp;amp; assigned Eth 1/9 to it&lt;BR /&gt;o Created ISP_Comcast &amp;amp; have not assigned eth 1/12 yet&lt;BR /&gt;o Created Trust for LAN networks&lt;BR /&gt;o Created Azure-S2S with Tunnel.1 &amp;amp; .2 (for failover)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;• Created two virtual routers one for each ISP link:&lt;BR /&gt;o Primary-ISP-Comcast (will have ethernet 1/12 assigned)&lt;BR /&gt;o Secondary-ISP-ATT&lt;BR /&gt; Eth 1/9 is for AT&amp;amp;T ISP/Link&lt;BR /&gt; Eth 1/10 is for PC connected directly&lt;BR /&gt; Tunnnel.2 for Asure S2S VPN (as a backup route)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;o For Statis Routes for Primary-ISP-Comcast, do I create just Comcast’s network with its next-hop IP (which is already created)? And what about the other internal networks? Do I need to create for each internal/LAN network a route to point to the next VR, which in this case is AT&amp;amp;T ISP or Comcast?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;o For the static routes for Secondary-ISP-ATT, besides configuring AT&amp;amp;T's next-hop IP address, what else would I need to do?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;• Also, for the static route in IPv4, do I need to enable “Path Monitoring”?&lt;BR /&gt;• Finally, the PBF, is my understanding is that in the “Forwarding” tab, I need to enter Comcast’s IP address and monitor it as well so that if it fails, all traffic is routed out of the AT&amp;amp;T ISP link, right?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you all!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#dualisp #PFB #virtualrouters #staticRoutes&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 20:20:27 GMT</pubDate>
    <dc:creator>FreddyC</dc:creator>
    <dc:date>2022-05-31T20:20:27Z</dc:date>
    <item>
      <title>DUAL ISP and PFB with single or multiple Virtual Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-pfb-with-single-or-multiple-virtual-routers/m-p/496236#M105153</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Palo Alto Community! I am reaching out because I am stuck and a bit confused about what I've seen online when it comes to configuring dual ISP and PFB (which that part I understand) but when configuring the Virtual Routers section. Some only create a single VR with both ISP and their next hops and others create their ISP each VRs and then there is a return internal network and their next hop is a VR. Here's what I have done so far:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have two ISPs (Comcast &amp;amp; AT&amp;amp;T) and would like for both of these ISP links to be routing traffic. I have read and reviewed a few Palo Alto-supported documentation &amp;amp; blogs from other sites. I've configured a few things on our firewall but I am not 100% clear on a few configurations that I have done to make sure it will work properly before going live.&lt;BR /&gt;&lt;BR /&gt;Here's what I've done so far:&lt;BR /&gt;&lt;BR /&gt;• Interfaces:&lt;BR /&gt;o Eth. 1/1 (native VLAN) and along subinterfaces for LAN&lt;BR /&gt;o Eth. 1/10 for AT&amp;amp;T ISP Link&lt;BR /&gt;o Eth. 1/12 for Comcast ISP Link&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;• Zones:&lt;BR /&gt;o Created ISP_ATT &amp;amp; assigned Eth 1/9 to it&lt;BR /&gt;o Created ISP_Comcast &amp;amp; have not assigned eth 1/12 yet&lt;BR /&gt;o Created Trust for LAN networks&lt;BR /&gt;o Created Azure-S2S with Tunnel.1 &amp;amp; .2 (for failover)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;• Created two virtual routers one for each ISP link:&lt;BR /&gt;o Primary-ISP-Comcast (will have ethernet 1/12 assigned)&lt;BR /&gt;o Secondary-ISP-ATT&lt;BR /&gt; Eth 1/9 is for AT&amp;amp;T ISP/Link&lt;BR /&gt; Eth 1/10 is for PC connected directly&lt;BR /&gt; Tunnnel.2 for Asure S2S VPN (as a backup route)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;o For Statis Routes for Primary-ISP-Comcast, do I create just Comcast’s network with its next-hop IP (which is already created)? And what about the other internal networks? Do I need to create for each internal/LAN network a route to point to the next VR, which in this case is AT&amp;amp;T ISP or Comcast?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;o For the static routes for Secondary-ISP-ATT, besides configuring AT&amp;amp;T's next-hop IP address, what else would I need to do?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;• Also, for the static route in IPv4, do I need to enable “Path Monitoring”?&lt;BR /&gt;• Finally, the PBF, is my understanding is that in the “Forwarding” tab, I need to enter Comcast’s IP address and monitor it as well so that if it fails, all traffic is routed out of the AT&amp;amp;T ISP link, right?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you all!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#dualisp #PFB #virtualrouters #staticRoutes&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 20:20:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-pfb-with-single-or-multiple-virtual-routers/m-p/496236#M105153</guid>
      <dc:creator>FreddyC</dc:creator>
      <dc:date>2022-05-31T20:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: DUAL ISP and PFB with single or multiple Virtual Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-pfb-with-single-or-multiple-virtual-routers/m-p/502102#M105290</link>
      <description>&lt;P&gt;the design depends on what you need&lt;/P&gt;
&lt;P&gt;if you simply want to double your bandwidth while providing redundancy, you can simply put everything on one VR and enable ECMP on both ISP links&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it gets a little more difficult once you start hosting services or need to set up redundant ipsec tunnels on both ISPs&lt;/P&gt;
&lt;P&gt;for hosted internal services you can keep using ECMP but you will need to create PBF rules that enable symmetric return, for fully redundant ipsec tunnels you'll want the multi-VR setup so the VPN traffic is more easily controlled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;lastly if you want to control which traffic is sent over each ISP, you can also use single VR with PBF rules sending trqffic to the appropriate ISP&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 09:03:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-pfb-with-single-or-multiple-virtual-routers/m-p/502102#M105290</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2022-06-09T09:03:57Z</dc:date>
    </item>
  </channel>
</rss>

