<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISP Failover and Global Protect (Routing Issues) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-and-global-protect-routing-issues/m-p/27399#M19973</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Hello All,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a pretty simple setup here - single PA-2020 with dual ISP's (One Virtual Router).&amp;nbsp; We're also using Global Protect (SSL VPN only) currently.&amp;nbsp; I seem to have an issue that I cannot sort out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP failover works great through the use of PBF.&amp;nbsp; All inbound services (policies and NAT continue to function) just fine...but here's the kicker.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Through the use of PBF routing all Internet bound traffic out my primary ISP, I should NOT (in theory) need a static route in my VR for this as PBF is checked first.&amp;nbsp; BUT - when this static route is removed, my Global Protect users can no longer connect to the firewall.&amp;nbsp; Adding this static route back with a LOWER metric than the route for my secondary ISP fixes the issue.&amp;nbsp; Obviously you can see where this can cause an issue when failed over to my secondary ISP (Primary ISP's default route has a lower metric and will attempt to be used first even though the route is disconnected).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I'm trying to do is setup something similar to a very basic IP SLA from the Cisco world.&amp;nbsp; I find it odd that the PA device can't seem to handle this alongside VPN connectivity in the very same way a Cisco PIX or ASA can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to avoid using multiple virtual routers if possible - any help would be appreciated!&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Jul 2012 17:53:51 GMT</pubDate>
    <dc:creator>computersupport</dc:creator>
    <dc:date>2012-07-09T17:53:51Z</dc:date>
    <item>
      <title>ISP Failover and Global Protect (Routing Issues)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-and-global-protect-routing-issues/m-p/27399#M19973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Hello All,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a pretty simple setup here - single PA-2020 with dual ISP's (One Virtual Router).&amp;nbsp; We're also using Global Protect (SSL VPN only) currently.&amp;nbsp; I seem to have an issue that I cannot sort out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP failover works great through the use of PBF.&amp;nbsp; All inbound services (policies and NAT continue to function) just fine...but here's the kicker.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Through the use of PBF routing all Internet bound traffic out my primary ISP, I should NOT (in theory) need a static route in my VR for this as PBF is checked first.&amp;nbsp; BUT - when this static route is removed, my Global Protect users can no longer connect to the firewall.&amp;nbsp; Adding this static route back with a LOWER metric than the route for my secondary ISP fixes the issue.&amp;nbsp; Obviously you can see where this can cause an issue when failed over to my secondary ISP (Primary ISP's default route has a lower metric and will attempt to be used first even though the route is disconnected).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I'm trying to do is setup something similar to a very basic IP SLA from the Cisco world.&amp;nbsp; I find it odd that the PA device can't seem to handle this alongside VPN connectivity in the very same way a Cisco PIX or ASA can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to avoid using multiple virtual routers if possible - any help would be appreciated!&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 17:53:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-and-global-protect-routing-issues/m-p/27399#M19973</guid>
      <dc:creator>computersupport</dc:creator>
      <dc:date>2012-07-09T17:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Failover and Global Protect (Routing Issues)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-and-global-protect-routing-issues/m-p/27400#M19974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check out this discussion thread: &lt;A __default_attr="5239" __jive_macro_name="thread" class="jive_macro jive_macro_thread" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2012 16:13:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-and-global-protect-routing-issues/m-p/27400#M19974</guid>
      <dc:creator>panagent</dc:creator>
      <dc:date>2012-08-17T16:13:18Z</dc:date>
    </item>
  </channel>
</rss>

