<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help to achieve IPsec VPN failover between Paloalto to Meraki in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543306#M111248</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/200155"&gt;@AKuzhuppilly&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2 branches have Paloalto and Meraki&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Branch A palo alto configured 2 Ipsec VPNs and same branch B Meraki configured 2 Ipsec vpn.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both IPSec tunnels are up but traffic is not passing...either I can disable the one tunnel the traffic is passing and wise versa. My requirement is needed to achieve the Ipsec failover between the two tunnels the peer end is Meraki.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly help and suggest how to solve the failover... I have already tried path monitor and tunnel monitor but no luck.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 May 2023 09:21:19 GMT</pubDate>
    <dc:creator>AhamadullahM</dc:creator>
    <dc:date>2023-05-25T09:21:19Z</dc:date>
    <item>
      <title>Need help to achieve IPsec VPN failover between Paloalto to Meraki</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543246#M111241</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Need help to achieve IPsec VPN failover between Paloalto to Meraki&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 19:21:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543246#M111241</guid>
      <dc:creator>AhamadullahM</dc:creator>
      <dc:date>2023-05-24T19:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to achieve IPsec VPN failover between Paloalto to Meraki</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543275#M111245</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Your question is not clear, can you explain what you are trying to achieve on the VPN failover part?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 02:47:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543275#M111245</guid>
      <dc:creator>akuzhuppilly</dc:creator>
      <dc:date>2023-05-25T02:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to achieve IPsec VPN failover between Paloalto to Meraki</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543306#M111248</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/200155"&gt;@AKuzhuppilly&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2 branches have Paloalto and Meraki&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Branch A palo alto configured 2 Ipsec VPNs and same branch B Meraki configured 2 Ipsec vpn.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both IPSec tunnels are up but traffic is not passing...either I can disable the one tunnel the traffic is passing and wise versa. My requirement is needed to achieve the Ipsec failover between the two tunnels the peer end is Meraki.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly help and suggest how to solve the failover... I have already tried path monitor and tunnel monitor but no luck.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 09:21:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543306#M111248</guid>
      <dc:creator>AhamadullahM</dc:creator>
      <dc:date>2023-05-25T09:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to achieve IPsec VPN failover between Paloalto to Meraki</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543314#M111249</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Still not clear. Can I confirm if your connectivity is as below?&lt;/P&gt;
&lt;DIV id="tinyMceEditor_4e8b4f88cd164akuzhuppilly_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA-Meraki.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50335i203E583CF42C4AEC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PA-Meraki.png" alt="PA-Meraki.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If so, the tunnel monitoring should be able to remove the route and point it to the secondary ISP (using IPSec 2) during a failure. What is the 'monitor profile' action? It should be set to 'failover'.&lt;/P&gt;
&lt;P&gt;You may refer to below KB:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POO0CAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POO0CAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 09:41:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543314#M111249</guid>
      <dc:creator>akuzhuppilly</dc:creator>
      <dc:date>2023-05-25T09:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to achieve IPsec VPN failover between Paloalto to Meraki</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543340#M111252</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204501"&gt;@AhamadullahM&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;To achieve IPsec failover you need both end of the tunnels to be able to detect issue and perform the failover, if only one side of the tunnel is performing the failover you will have asymmetric routing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From Palo Alto point of view the setup is as follow:&lt;/P&gt;
&lt;P&gt;- Palo Alto firewall is implementing route base VPN. Which means firewall relay on the routing table to decide which traffic to encrypt over each tunnel.&lt;/P&gt;
&lt;P&gt;- To achieve IPsec failover you need to have two IPsec tunnel configured and two static routes for destination network pointing to each tunnel.&lt;/P&gt;
&lt;P&gt;- By default PAN FW will not allow you to configure two static routes for same destination with exact same metric. Which means the second route will have higher metric - therefor in FIB only the first route will be installed and traffic will be sent over first tunnel.&lt;/P&gt;
&lt;P&gt;- Tunnel monitor will detect when tunnel have issues and "disable" the logical tunnel interface associated with that tunnel. Because the interface is "down" all routes associated with it will be removed from FIB and firewall will start using the second route and start sending traffic over second tunnel.&lt;/P&gt;
&lt;P&gt;- When tunnel monitor detect tunnel is up again, it will "enable" the tunnel interface and install the primary route (because it has the lowest metric) and start sending traffic over first tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So when you said "tried tunnel monitor, but no luck", you need to note that the cause could be in the Meraki.&lt;/P&gt;
&lt;P&gt;Can you please provide more information how is Meraki configured to perform tunnel failover?&lt;/P&gt;
&lt;P&gt;More details for "tried tunnel monitor, but no luck" - tunnel with the monitor went down even if it is actually up? Or traffic does not failover when first tunnel is down? What issue exactly do you experience?&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 13:50:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-help-to-achieve-ipsec-vpn-failover-between-paloalto-to/m-p/543340#M111252</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-05-25T13:50:48Z</dc:date>
    </item>
  </channel>
</rss>

