<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA with Two ISPs NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36100#M26529</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Parvez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 11 May 2014 06:28:06 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-05-11T06:28:06Z</dc:date>
    <item>
      <title>PA with Two ISPs NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36096#M26525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have four zone in the PA. The naming along with subnet are below mentioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. ISP1- 100.100.100.2/29&lt;/P&gt;&lt;P&gt;2. ISP2- 200.200.200.2/29&lt;/P&gt;&lt;P&gt;3. DMZ1- 172.16.1.1/24&lt;/P&gt;&lt;P&gt;4. DMZ2-172.10.1.1/24&lt;/P&gt;&lt;P&gt;5. Inside- 10.10.10.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside user are going to internet via ISP1 and ISP2 is used for accessing in the DMZ1 and DMZ2.&lt;/P&gt;&lt;P&gt;Since the default route is configured towards the ISP1&lt;EM&gt;. We are facing the issue to access the servers in DMZ1 and DMZ2 via ISP2.(Destination Nat is configured for these servers via ISP2).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;As per the logs the session from ISP2 to DMZ1 and ISP2 to DMZ2 are showing incomplete.I tried to configure PBF but it is not working.&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Kindly let me know how DMZ1 and DMZ2 servers can accessible via ISP2. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2014 14:21:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36096#M26525</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-05-08T14:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: PA with Two ISPs NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36097#M26526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hello Parvez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Here's a good document with a network diagram which can help. Symmetric return &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;eature&lt;/SPAN&gt; forwards the packet to the MAC address from where the SYN or lost packet was received.&amp;nbsp; This ensures return traffic follows the same interface which the session created and is useful in an asymmetric routing or Dual ISP environments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4344"&gt;How to Configure Symmetric Return &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2014 14:57:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36097#M26526</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-08T14:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA with Two ISPs NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36098#M26527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;also when wan interface's are ppoe you don't need to write next hop, just selecting enforce return works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2014 18:45:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36098#M26527</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-05-09T18:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: PA with Two ISPs NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36099#M26528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just want to double check that it will work for another DMZ2 host ; that is also need to be accessed via ISP2.&lt;/P&gt;&lt;P&gt;i.e. is PA-FW support two PBF on the same interface (ISP2) with different zone hosts(DMZ1 and DMZ2)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 May 2014 05:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36099#M26528</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-05-11T05:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: PA with Two ISPs NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36100#M26529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Parvez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 May 2014 06:28:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-with-two-isps-nat/m-p/36100#M26529</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-11T06:28:06Z</dc:date>
    </item>
  </channel>
</rss>

