<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect with Second ISP which not have a default route to internet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/522441#M108231</link>
    <description>&lt;P&gt;Well this look little challenging but I am guessing you are trying route GP traffic via second ISP. Did you try with PAT for second ISP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;let's say your GP source subnet is 192.168.10.0/24, and Zone is GP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your PAT -&lt;/P&gt;
&lt;P&gt;Source GP Zone /&amp;nbsp;192.168.10.0/24&lt;/P&gt;
&lt;P&gt;Destination Outside Zone / Public IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Same for Security Policy rule for accepted outbound traffic&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Nov 2022 14:27:30 GMT</pubDate>
    <dc:creator>Bharat_Rajwanshi</dc:creator>
    <dc:date>2022-11-25T14:27:30Z</dc:date>
    <item>
      <title>Global Protect with Second ISP which not have a default route to internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/522424#M108227</link>
      <description>&lt;P&gt;The issue is due to the static route of 0.0.0.0 is through the First ISP. Tried to add the PBF but still the same behavior even with symmetric return&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advise ? Know the option if another Virtual router , but with one single VR , is there any way ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 09:30:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/522424#M108227</guid>
      <dc:creator>sambhusarath</dc:creator>
      <dc:date>2022-11-25T09:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect with Second ISP which not have a default route to internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/522441#M108231</link>
      <description>&lt;P&gt;Well this look little challenging but I am guessing you are trying route GP traffic via second ISP. Did you try with PAT for second ISP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;let's say your GP source subnet is 192.168.10.0/24, and Zone is GP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your PAT -&lt;/P&gt;
&lt;P&gt;Source GP Zone /&amp;nbsp;192.168.10.0/24&lt;/P&gt;
&lt;P&gt;Destination Outside Zone / Public IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Same for Security Policy rule for accepted outbound traffic&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 14:27:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/522441#M108231</guid>
      <dc:creator>Bharat_Rajwanshi</dc:creator>
      <dc:date>2022-11-25T14:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect with Second ISP which not have a default route to internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/522474#M108237</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/210927"&gt;@sambhusarath&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Can you share your PBF configuration?&lt;/P&gt;
&lt;P&gt;Following link describe setup similar to what you want to achieve - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF5CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF5CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;As you can see PBF with Enforce Symmetric return should provide you with required result - return the replies from GP via secondary ISP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I am assuming something is not configured properly with your PBF. Try to follow the setups from the link and if still not working we can try to troubleshoot.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2022 10:09:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/522474#M108237</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-11-27T10:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect with Second ISP which not have a default route to internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/704213#M122203</link>
      <description>&lt;P&gt;Can you reshare this KB ?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 16:23:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/704213#M122203</guid>
      <dc:creator>sambhusarath</dc:creator>
      <dc:date>2024-11-26T16:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect with Second ISP which not have a default route to internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/704671#M122213</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If you have two ISP's and just want failover, use PBF for the primary with the policy to shut down if path not detected. Then the default route points to the second ISP.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 22:51:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-second-isp-which-not-have-a-default-route-to/m-p/704671#M122213</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-11-26T22:51:50Z</dc:date>
    </item>
  </channel>
</rss>

