<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Backup Internet with Ipsec VPN doing BGP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/backup-internet-with-ipsec-vpn-doing-bgp/m-p/1226984#M124056</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Mostly just need a sanity check on this configuration.&lt;BR /&gt;&lt;BR /&gt;I am setting up a backup internet for one of our hub sites as a failover.&lt;/P&gt;
&lt;P&gt;Currently the connection to the other primary sites is via a IPsec tunnel using iBGP to pass routes between the "Hub" sites as well as redist into OSPF for internal traffic and routing to spokes.&lt;BR /&gt;&lt;BR /&gt;The External VR has a default route to the primary ISP with path monitoring set to metric 10, and a second default route to the backup ISP on metric 100. &lt;BR /&gt;&lt;BR /&gt;I have created new tunnel interfaces, ike gateways and ipsec tunnels on both sides for the backup internet connection under a different subnet&lt;BR /&gt;&lt;BR /&gt;I am adding the second tunnel to the same Peer groups (one for each Hub Connection).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;From my understanding I shouldn’t need to worry about adjusting the new peers AS, MED, etc. in the peer groups as only one of the sessions could be alive at any given time due to the external routers default route metrics.&lt;BR /&gt;&lt;BR /&gt;Am I missing anything here, and even through I shouldn't have to set the new peers to only be used as a failover connection in BGP should I do it anyway?&lt;/P&gt;</description>
    <pubDate>Mon, 21 Apr 2025 15:26:57 GMT</pubDate>
    <dc:creator>CaseyAnderson</dc:creator>
    <dc:date>2025-04-21T15:26:57Z</dc:date>
    <item>
      <title>Backup Internet with Ipsec VPN doing BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/backup-internet-with-ipsec-vpn-doing-bgp/m-p/1226984#M124056</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Mostly just need a sanity check on this configuration.&lt;BR /&gt;&lt;BR /&gt;I am setting up a backup internet for one of our hub sites as a failover.&lt;/P&gt;
&lt;P&gt;Currently the connection to the other primary sites is via a IPsec tunnel using iBGP to pass routes between the "Hub" sites as well as redist into OSPF for internal traffic and routing to spokes.&lt;BR /&gt;&lt;BR /&gt;The External VR has a default route to the primary ISP with path monitoring set to metric 10, and a second default route to the backup ISP on metric 100. &lt;BR /&gt;&lt;BR /&gt;I have created new tunnel interfaces, ike gateways and ipsec tunnels on both sides for the backup internet connection under a different subnet&lt;BR /&gt;&lt;BR /&gt;I am adding the second tunnel to the same Peer groups (one for each Hub Connection).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;From my understanding I shouldn’t need to worry about adjusting the new peers AS, MED, etc. in the peer groups as only one of the sessions could be alive at any given time due to the external routers default route metrics.&lt;BR /&gt;&lt;BR /&gt;Am I missing anything here, and even through I shouldn't have to set the new peers to only be used as a failover connection in BGP should I do it anyway?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 15:26:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/backup-internet-with-ipsec-vpn-doing-bgp/m-p/1226984#M124056</guid>
      <dc:creator>CaseyAnderson</dc:creator>
      <dc:date>2025-04-21T15:26:57Z</dc:date>
    </item>
  </channel>
</rss>

