<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic static routes for 2 wan links with DHCP dynamic IPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/static-routes-for-2-wan-links-with-dhcp-dynamic-ips/m-p/564370#M114202</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to ask for some assistance in my configuration, the palo alto firewall has been so far a pretty frustrating experience, I guess due to my lack of knowledge of Pas&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have 2 wan dhcp dynamic ips links&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to implement some redundancy&lt;/P&gt;
&lt;P&gt;if 1 link goes down - the second link activates and when the primary goes back, it failovers back&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;very simple setting&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hav dhcp enabled on both interfaces and I have disabled "automatically install the default route from the isp"&lt;/P&gt;
&lt;P&gt;I went to logical routes and created:&lt;/P&gt;
&lt;P&gt;a static route 1&amp;nbsp; with metric 10 : 0.0.0.0/0 --&amp;gt; next hope "none" and interface being the wan 1 (I have a dynamic next hop, so i cannot point to the temp gateway)&lt;/P&gt;
&lt;P&gt;a static route 2&amp;nbsp; with metric 200 : 0.0.0.0/0 --&amp;gt; next hope "none" and interface being&amp;nbsp; the wan 2&amp;nbsp;I have a dynamic next hop, so i cannot point to the temp gateway)&lt;/P&gt;
&lt;P&gt;enabled route&amp;nbsp; monitoring and after installing I get&lt;/P&gt;
&lt;P&gt;Path monitoring failed for static route destination 0.0.0.0/0 with next hop ethernet1/2. Route removed.&lt;BR /&gt;11/04 06:04:28&lt;BR /&gt;Path monitoring failed for static route destination 0.0.0.0/0 with next hop ethernet1/1. Route removed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so obviously after that internet is not working&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you please advise what do i do wrong, why the PA cannot identity the next hop dinamically via the interface it was told to use??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Nov 2023 21:08:43 GMT</pubDate>
    <dc:creator>nevolex</dc:creator>
    <dc:date>2023-11-03T21:08:43Z</dc:date>
    <item>
      <title>static routes for 2 wan links with DHCP dynamic IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-routes-for-2-wan-links-with-dhcp-dynamic-ips/m-p/564370#M114202</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to ask for some assistance in my configuration, the palo alto firewall has been so far a pretty frustrating experience, I guess due to my lack of knowledge of Pas&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have 2 wan dhcp dynamic ips links&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to implement some redundancy&lt;/P&gt;
&lt;P&gt;if 1 link goes down - the second link activates and when the primary goes back, it failovers back&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;very simple setting&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hav dhcp enabled on both interfaces and I have disabled "automatically install the default route from the isp"&lt;/P&gt;
&lt;P&gt;I went to logical routes and created:&lt;/P&gt;
&lt;P&gt;a static route 1&amp;nbsp; with metric 10 : 0.0.0.0/0 --&amp;gt; next hope "none" and interface being the wan 1 (I have a dynamic next hop, so i cannot point to the temp gateway)&lt;/P&gt;
&lt;P&gt;a static route 2&amp;nbsp; with metric 200 : 0.0.0.0/0 --&amp;gt; next hope "none" and interface being&amp;nbsp; the wan 2&amp;nbsp;I have a dynamic next hop, so i cannot point to the temp gateway)&lt;/P&gt;
&lt;P&gt;enabled route&amp;nbsp; monitoring and after installing I get&lt;/P&gt;
&lt;P&gt;Path monitoring failed for static route destination 0.0.0.0/0 with next hop ethernet1/2. Route removed.&lt;BR /&gt;11/04 06:04:28&lt;BR /&gt;Path monitoring failed for static route destination 0.0.0.0/0 with next hop ethernet1/1. Route removed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so obviously after that internet is not working&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you please advise what do i do wrong, why the PA cannot identity the next hop dinamically via the interface it was told to use??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 21:08:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-routes-for-2-wan-links-with-dhcp-dynamic-ips/m-p/564370#M114202</guid>
      <dc:creator>nevolex</dc:creator>
      <dc:date>2023-11-03T21:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: static routes for 2 wan links with DHCP dynamic IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-routes-for-2-wan-links-with-dhcp-dynamic-ips/m-p/564384#M114206</link>
      <description>&lt;P&gt;Static route you try to configure will be removed from virtual router only if interface physically goes down.&lt;/P&gt;
&lt;P&gt;If you would have static IPs from ISP you could set up path monitoring inside the static route.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What you are trying to accomplish is as good as leaving "&lt;SPAN&gt;automatically install the default route from the isp" in place and setting route metric on one DHCP interface to 10 and 200 on other.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1699061520588.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54960iA8903135CECF6D9A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1699061520588.png" alt="Raido_Rattameister_0-1699061520588.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can't configure path monitoring if your interface don't have IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Theoretically you could wait for DHCP to pick up gateway IP and then set up PBF with next hop to that gateway IP.&lt;/P&gt;
&lt;P&gt;And then second PBF under first one towards secondary ISP.&lt;/P&gt;
&lt;P&gt;If your ISP don't change subnet then gateway should be more or less the same all the time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As PBF is processed before virtual router if there is matching PBF then virtual router is bypassed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 01:41:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-routes-for-2-wan-links-with-dhcp-dynamic-ips/m-p/564384#M114206</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-04T01:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: static routes for 2 wan links with DHCP dynamic IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-routes-for-2-wan-links-with-dhcp-dynamic-ips/m-p/564389#M114210</link>
      <description>&lt;P&gt;Thank you for your reply&amp;nbsp;&lt;A class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603" target="_self" aria-label="View Profile of Raido_Rattameister"&gt;&lt;SPAN class="login-bold"&gt;Raido_Rattameister&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603" target="_blank"&gt;I will&lt;/A&gt; use your suggestion, would you know how in this case configure the static router for sdwan? Thank you&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 07:33:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-routes-for-2-wan-links-with-dhcp-dynamic-ips/m-p/564389#M114210</guid>
      <dc:creator>nevolex</dc:creator>
      <dc:date>2023-11-04T07:33:19Z</dc:date>
    </item>
  </channel>
</rss>

