<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP stops working when ecmp is enabled in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565210#M114308</link>
    <description>&lt;P&gt;Hi Raido,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried this pbr rule but it didn’t work:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;source - leased line interface&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destination - any&lt;/P&gt;
&lt;P&gt;next hop - gateway of leased line isp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Isn’t it the same?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2023 19:57:26 GMT</pubDate>
    <dc:creator>Dijesh</dc:creator>
    <dc:date>2023-11-10T19:57:26Z</dc:date>
    <item>
      <title>GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565190#M114304</link>
      <description>&lt;P&gt;We have Palo Alto firewall with three Internet links. One is a leased line and other two are ADSL links. I have configured ECMP on the two ADSL lines to load balance traffic on the two ADSL links. Global Protect is configured on the leased line. I have configured default route to all the three internet links in the firewall. I have configured the default route for leased line with AD and metric to be lower than that of the ADSL links, then the global protect works fine, however the ADSL links do not appear in the FIB and thereby traffic does not go through the ADSL links. If the default route for the ADSL links are configured&amp;nbsp;with AD and metric lower than that of leased line, the ADSL links appear in the FIB and loadbalancing of traffic over ADSL links work fine, however the global protect does not work as the default route for leased line is not added to FIB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestions so that the load balancing is done on the ADSL links and global protect works fine?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 17:03:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565190#M114304</guid>
      <dc:creator>Dijesh</dc:creator>
      <dc:date>2023-11-10T17:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565194#M114305</link>
      <description>&lt;P&gt;What is your ideal goal? Which links you want to use for Internet and which not?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 18:17:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565194#M114305</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-10T18:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565201#M114306</link>
      <description>&lt;P&gt;Hi Raido,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;leased line for global protect&lt;/P&gt;
&lt;P&gt;Two adsl links for user internet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 18:48:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565201#M114306</guid>
      <dc:creator>Dijesh</dc:creator>
      <dc:date>2023-11-10T18:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565204#M114307</link>
      <description>&lt;P&gt;Virtual router can only route based on destination IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set up ADSL links with same AD and metric.&lt;/P&gt;
&lt;P&gt;ECMP will load balance outgoing traffic over those links.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For GlobalProtect set up PBF&lt;/P&gt;
&lt;P&gt;Policies &amp;gt; Policy Based Forwarding&lt;/P&gt;
&lt;P&gt;Source zone - GlobalProtect&lt;/P&gt;
&lt;P&gt;Destination IP - "Not RFC1918 IP"&lt;/P&gt;
&lt;P&gt;Next hop - Leased line ISP IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PBF policies are checked before virtual router.&lt;/P&gt;
&lt;P&gt;If any of PBF policies match then traffic will be routed accordingly and virtual router won't be checked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 19:20:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565204#M114307</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-10T19:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565210#M114308</link>
      <description>&lt;P&gt;Hi Raido,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried this pbr rule but it didn’t work:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;source - leased line interface&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destination - any&lt;/P&gt;
&lt;P&gt;next hop - gateway of leased line isp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Isn’t it the same?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 19:57:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565210#M114308</guid>
      <dc:creator>Dijesh</dc:creator>
      <dc:date>2023-11-10T19:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565217#M114310</link>
      <description>&lt;P&gt;No it is not the same because GlobalProtect traffic is not coming from leased line interface but it is arriving into Palo from GlobalProtect zone.&lt;/P&gt;
&lt;P&gt;Tunnel interface that is configured in GlobalProtect gateway config has dedicated zone assigned or are you using genera INSIDE zone for that?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 21:40:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565217#M114310</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-10T21:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565233#M114318</link>
      <description>&lt;P&gt;Hi Raido,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my case, the global protect agent is not getting connected&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2023 03:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565233#M114318</guid>
      <dc:creator>Dijesh</dc:creator>
      <dc:date>2023-11-11T03:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565234#M114319</link>
      <description>&lt;P&gt;Probably because replies to incoming GlobalProtect connection attempts get response back from ADSL interface due routing preference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No good solution.&lt;/P&gt;
&lt;P&gt;I guess best is to set up dedicated virtual router for leased line.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2023 03:48:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565234#M114319</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-11T03:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565270#M114324</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/229020"&gt;@Dijesh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enable Symmetric Return for ECMP and GP should work fine.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/network/network-virtual-routers/ecmp/ecmp-settings" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/network/network-virtual-routers/ecmp/ecmp-settings&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your scenario is the reason the Symmetric Return option is there.&amp;nbsp; We want the GP return packets to &lt;U&gt;always&lt;/U&gt; go out the same interface they came in and not be load balanced.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 00:30:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565270#M114324</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-11-13T00:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565289#M114325</link>
      <description>&lt;P&gt;Symmetric return overrides ECMP load balancing algorithm but it does not override fact that 0.0.0.0/0 route towards leased line does not exist in the forwarding table.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Default route towards leased line can't have same ad/metric because then outgoing traffic would also start using it.&lt;/P&gt;
&lt;P&gt;Symmetric return would help only if all 3 ISP links (leased line and 2x ADSL) would have same AD and metric.&lt;/P&gt;
&lt;P&gt;As goal is to load balance outgoing traffic out over both ADSL links (and not leased line) only feasible option is to place leased line interface into it's own virtual router.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Theoretically you could try to change load balance algorithm to "Weighted Round Robin", add all 3 ISP interfaces into the list, set both ADSL link weights to 255 and leased line weight to 1.&lt;BR /&gt;In this case only tiny amount of sessions would take outgoing path over leased line but it would not be completely zero. Benefit would be that all ISP links stay in same virtual router.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 03:35:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565289#M114325</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-13T03:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565291#M114327</link>
      <description>&lt;P&gt;Hi Raido,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your suggestions. Assigning the leased line to a separate virtual router fixed the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 03:44:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565291#M114327</guid>
      <dc:creator>Dijesh</dc:creator>
      <dc:date>2023-11-13T03:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: GP stops working when ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565334#M114333</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for clarifying the design.&amp;nbsp; I missed that part.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/229020"&gt;@Dijesh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are glad it is working!&amp;nbsp; Please mark &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt; reply as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 10:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-stops-working-when-ecmp-is-enabled/m-p/565334#M114333</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-11-13T10:18:20Z</dc:date>
    </item>
  </channel>
</rss>

