<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internet load balancing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/internet-load-balancing/m-p/34311#M25166</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many Thanks brother Mikand for your reply.&lt;/P&gt;&lt;P&gt;my concern we have 5 connections in these connections we have 2 dedicated internet links with 25m and we need to configure the 5 untrust zones and use PBF to add rules like IT group will forward to dedicated link number 1 which has 25mb and configure another rule for IT group to use dedicated link No. 2 in case first one goes down. and another AD groups we will decide to which link they can leave using PBF.&lt;/P&gt;&lt;P&gt;LAN ------------ PA -----------------untrust-1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------------untrust-2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------------untrust-3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------------untrust-4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------------untrust-5&lt;/P&gt;&lt;P&gt;for this scenario we supose to use 6 interfaces one as trust (LAN) and 5 untrust (Internet zones).&lt;/P&gt;&lt;P&gt;for this scenario could you please inform me what is the best practice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H5 class="simple"&gt;&lt;/H5&gt;&lt;H5 class="simple"&gt;&lt;/H5&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Apr 2013 14:38:10 GMT</pubDate>
    <dc:creator>AymanShimy</dc:creator>
    <dc:date>2013-04-04T14:38:10Z</dc:date>
    <item>
      <title>Internet load balancing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-load-balancing/m-p/34309#M25164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi i have 5 internet connections (two dedicated links with different ISPs and 3 shared links with one ISP) , I need to configure the 5 untrust zones for internet and one for trust how i can configure the VR and how i can i use PBF per group of users. and create a backup link in case the first internet link goes down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 16:59:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-load-balancing/m-p/34309#M25164</guid>
      <dc:creator>AymanShimy</dc:creator>
      <dc:date>2013-04-03T16:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: Internet load balancing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-load-balancing/m-p/34310#M25165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PA currently doesnt support ECMP according to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/message/18957#18957" title="https://live.paloaltonetworks.com/message/18957#18957"&gt;https://live.paloaltonetworks.com/message/18957#18957&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="23879" __jive_macro_name="message" class="jive_macro jive_macro_message" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which gives that if you wish to use all your 5 internet connections at once I would suggest you to use a router in front of your PA to do the routing and from that router use a single linknet which you then route the /24 or whatever you have assigned towards the PA unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way the PA unit wont have to care about which connection was/is being used - for redundancy you can setup aggregated interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result would be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Internet (5 x connections)&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;2) Router (BGP preferly, but static would work aswell towards your ISPs)&lt;/P&gt;&lt;P&gt;[10.0.0.6/29]&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;[10.0.0.1/29]&lt;/P&gt;&lt;P&gt;3) PA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your router would have a routing table similar to (regarding PA):&lt;/P&gt;&lt;P&gt;x.x.x.x/24 next 10.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;while your PA device would have:&lt;/P&gt;&lt;P&gt;0.0.0.0/0 next 10.0.0.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: Ahem *coughs*, highest usuable ip in the range 10.0.0.0/29 is 10.0.0.6 and not 10.0.0.7 which is the broadcast but I think you already got the point &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 19:53:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-load-balancing/m-p/34310#M25165</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-04-03T19:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Internet load balancing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-load-balancing/m-p/34311#M25166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many Thanks brother Mikand for your reply.&lt;/P&gt;&lt;P&gt;my concern we have 5 connections in these connections we have 2 dedicated internet links with 25m and we need to configure the 5 untrust zones and use PBF to add rules like IT group will forward to dedicated link number 1 which has 25mb and configure another rule for IT group to use dedicated link No. 2 in case first one goes down. and another AD groups we will decide to which link they can leave using PBF.&lt;/P&gt;&lt;P&gt;LAN ------------ PA -----------------untrust-1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------------untrust-2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------------untrust-3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------------untrust-4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------------untrust-5&lt;/P&gt;&lt;P&gt;for this scenario we supose to use 6 interfaces one as trust (LAN) and 5 untrust (Internet zones).&lt;/P&gt;&lt;P&gt;for this scenario could you please inform me what is the best practice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H5 class="simple"&gt;&lt;/H5&gt;&lt;H5 class="simple"&gt;&lt;/H5&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Apr 2013 14:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-load-balancing/m-p/34311#M25166</guid>
      <dc:creator>AymanShimy</dc:creator>
      <dc:date>2013-04-04T14:38:10Z</dc:date>
    </item>
  </channel>
</rss>

