<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Testing the quality of the main link in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/testing-the-quality-of-the-main-link/m-p/995604#M122244</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The ISP had a failure on its side, which involved slow connection, which made it difficult for people inside the company and those working on VPN to work. We have a backup connection that switches in the event of a failure of the main connection. Is it possible to introduce a mechanism that tests the throughput of the main connection and, in the event of a drop in speed and quality, switches to the second one.&lt;/P&gt;
&lt;P&gt;Additionally, can I configure one portal in Global Protec that will refer to two addresses? So that when it is not possible to connect to the first address, it will try to connect to the second one?&lt;/P&gt;</description>
    <pubDate>Thu, 28 Nov 2024 08:57:16 GMT</pubDate>
    <dc:creator>D.Drzyzga</dc:creator>
    <dc:date>2024-11-28T08:57:16Z</dc:date>
    <item>
      <title>Testing the quality of the main link</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/testing-the-quality-of-the-main-link/m-p/995604#M122244</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The ISP had a failure on its side, which involved slow connection, which made it difficult for people inside the company and those working on VPN to work. We have a backup connection that switches in the event of a failure of the main connection. Is it possible to introduce a mechanism that tests the throughput of the main connection and, in the event of a drop in speed and quality, switches to the second one.&lt;/P&gt;
&lt;P&gt;Additionally, can I configure one portal in Global Protec that will refer to two addresses? So that when it is not possible to connect to the first address, it will try to connect to the second one?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 08:57:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/testing-the-quality-of-the-main-link/m-p/995604#M122244</guid>
      <dc:creator>D.Drzyzga</dc:creator>
      <dc:date>2024-11-28T08:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Testing the quality of the main link</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/testing-the-quality-of-the-main-link/m-p/995747#M122268</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1044684505"&gt;@D.Drzyzga&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Slow connections isn't something that the firewall can really monitor by itself. You would need an outside process such as a monitoring script(s) that can monitor both connections and that could then either alert you of a potential issue, or automatically failover traffic via the API if you wish to bring things that far. The firewall can monitor for an entire failure through path monitoring, but that external step is needed to true performance monitoring.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for your GlobalProtect question, the firewall itself can't push out an agent configuration that has two addresses tied to a single portal address. You would generally utilize something like a load-balancer or dynamic DNS to perform something like that so you could quickly migrate traffic to that portal address to your other address.&lt;/P&gt;
&lt;P&gt;Keep in mind that portal caching is a thing, so if you have multiple gateways configured (one on each connection) your portal doesn't really need to be active for existing endpoints. The GlobalProtect agent will use the cached portal configuration when the portal is not reachable, and if you have both of your gateways included it will connect to the gateway that is online. Keep in mind that in the scenario that you're describing where you don't have a full outage, you'll need to manually down the portal/gateway to get this to behave properly. A slow connection is one of those things that kind of requires manual interaction on your end more than an actual failure would, as you want to identify that and just bring that bad connection down.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 13:48:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/testing-the-quality-of-the-main-link/m-p/995747#M122268</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-11-29T13:48:55Z</dc:date>
    </item>
  </channel>
</rss>

