<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2 isps 1 for ipsec tunnel 1 for user  internet advice on how to do this in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565963#M114415</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/297417"&gt;@din100&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The easiest way to accomplish your goal is to use a default route to 2.2.2.1 and host routes (/32) to 3.3.3.1 for each VPN peer.&amp;nbsp; Routing to each IPsec tunnel interface (static or dynamic) will ensure the tunneled traffic is routed correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mentioned that the IPsec peers only accept the 1 IP address.&amp;nbsp; So, you do not have to plan for IPsec redundancy.&amp;nbsp; If you want redundancy for Internet traffic, you could follow this guide.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 16 Nov 2023 10:45:24 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-11-16T10:45:24Z</dc:date>
    <item>
      <title>2 isps 1 for ipsec tunnel 1 for user  internet advice on how to do this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565952#M114411</link>
      <description>&lt;P&gt;Hi Guys hope this a quick one,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have 2 ISPs want to use 1 for the site to site tunnels and 1 for the user internet&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created 2 interfaces for 2 isps&lt;/P&gt;
&lt;P&gt;interface 1/1 with 2.2.2.2 next hop 2.2.2.1 (isp for internet access some site to site )&lt;/P&gt;
&lt;P&gt;interface 1/2 with 3.3.3.3 next hop 3.3.3.1 ( only for some site to site they only allow this ips)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Created a virtual router call VR1&lt;/P&gt;
&lt;P&gt;routes for 0.0.0.0&amp;nbsp; &amp;nbsp;2.2.2.1 metric 10&lt;/P&gt;
&lt;P&gt;routes for 0.0.0.0 next hop&amp;nbsp; 3.3.3.1&amp;nbsp;metric 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have NAT rules for Both ISPs&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's letting me select site to site with each ISP and internet works on the primary.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not tested on the live environment it might not work or is their a better way to do this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 09:10:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565952#M114411</guid>
      <dc:creator>din100</dc:creator>
      <dc:date>2023-11-16T09:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: 2 isps 1 for ipsec tunnel 1 for user  internet advice on how to do this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565962#M114414</link>
      <description>&lt;P&gt;I can't seems to edit it&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;routes for 0.0.0.0 next hop&amp;nbsp; 3.3.3.1&amp;nbsp;metric 20 not 10 as I posted above&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 10:38:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565962#M114414</guid>
      <dc:creator>din100</dc:creator>
      <dc:date>2023-11-16T10:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: 2 isps 1 for ipsec tunnel 1 for user  internet advice on how to do this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565963#M114415</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/297417"&gt;@din100&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The easiest way to accomplish your goal is to use a default route to 2.2.2.1 and host routes (/32) to 3.3.3.1 for each VPN peer.&amp;nbsp; Routing to each IPsec tunnel interface (static or dynamic) will ensure the tunneled traffic is routed correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mentioned that the IPsec peers only accept the 1 IP address.&amp;nbsp; So, you do not have to plan for IPsec redundancy.&amp;nbsp; If you want redundancy for Internet traffic, you could follow this guide.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 10:45:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565963#M114415</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-11-16T10:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: 2 isps 1 for ipsec tunnel 1 for user  internet advice on how to do this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565969#M114418</link>
      <description>&lt;P&gt;ok so you are saying remove routes for 0.0.0.0 next hop 3.3.3.1 metric 20&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;add each VPN peer like 7.7.7.7 next hop to 3.3.3.1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;nice I will try it&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 11:20:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565969#M114418</guid>
      <dc:creator>din100</dc:creator>
      <dc:date>2023-11-16T11:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: 2 isps 1 for ipsec tunnel 1 for user  internet advice on how to do this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565980#M114420</link>
      <description>&lt;P&gt;Yes!&amp;nbsp; Add each VPN peer host route like your example.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can keep the 2nd default route with the higher metric.&amp;nbsp; It will be used if the link goes down.&amp;nbsp; You can also add path monitoring which will allow failover if the ISP has connectivity problems.&amp;nbsp; My path monitoring configuration is different than the URL I posted.&amp;nbsp; I do not ping the ISP gateway because occasionally the gateway can remain up when the Internet is down.&amp;nbsp; I ping 2 public IP addresses and set the failure condition to all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 12:27:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565980#M114420</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-11-16T12:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: 2 isps 1 for ipsec tunnel 1 for user  internet advice on how to do this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565986#M114423</link>
      <description>&lt;P&gt;Good point our ISP gateway is inside our building :D. I will change it to google/cloudflair dns ips.&amp;nbsp; thank you so much for your help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 13:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/565986#M114423</guid>
      <dc:creator>din100</dc:creator>
      <dc:date>2023-11-16T13:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: 2 isps 1 for ipsec tunnel 1 for user  internet advice on how to do this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/567013#M114558</link>
      <description>&lt;P&gt;thank you again Tom, all worked like a clock work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 11:17:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-isps-1-for-ipsec-tunnel-1-for-user-internet-advice-on-how-to/m-p/567013#M114558</guid>
      <dc:creator>din100</dc:creator>
      <dc:date>2023-11-24T11:17:07Z</dc:date>
    </item>
  </channel>
</rss>

