<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External IPs with two ISPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/external-ips-with-two-isps/m-p/45176#M33193</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like PBF (Policy Based Forwarding) could be the solution for your case:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3220" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way you can setup so (for example) web-browsing will function through ispA incase ispB goes down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This one should be helpful aswell:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3579" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Aug 2012 03:31:37 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-08-29T03:31:37Z</dc:date>
    <item>
      <title>External IPs with two ISPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-ips-with-two-isps/m-p/45175#M33192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a special setup on our external firewall interfaces. There are two different Internet lines from two different ISPs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NetDrawing.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3895_NetDrawing.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The yellow line (ISP b) indiaces the main Internet line. The green one is currently only used for outgoing e-mails using the "main" IP address 212.x.x.6. Now we would like to activate an additional IP range assigned by our ISP a: 212.x.x.96/28. We would like to use it the same way as the external IP addresses in the subnet of ISP b. The public IPs should be "assigned" to the firewall and it should be possible to NAT from 212.x.x.96/28 to internal IPs. Of course outgoing SNAT should work as well for traffic we policy route through that ISP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please give us some hints how we could implement this additional IP range? Do we need to create a loopback interface for that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2012 10:23:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-ips-with-two-isps/m-p/45175#M33192</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-08-28T10:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: External IPs with two ISPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-ips-with-two-isps/m-p/45176#M33193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like PBF (Policy Based Forwarding) could be the solution for your case:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3220" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way you can setup so (for example) web-browsing will function through ispA incase ispB goes down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This one should be helpful aswell:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3579" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2012 03:31:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-ips-with-two-isps/m-p/45176#M33193</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-08-29T03:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: External IPs with two ISPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-ips-with-two-isps/m-p/45177#M33194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you mikand. The two docs are pretty interesting and I'll study them carefully to setup a proper redundancy. The issue I posted is another one. On ISP "a" (green part in the drawing) we have two different IP subnets available:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subnet 1:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Subnet ID: 212.x.x.4/30&lt;/LI&gt;&lt;LI&gt;Default Gw: 212.x.x.5 (ISP a router)&lt;/LI&gt;&lt;LI&gt;212.x.x.6 is assigned to the firewall&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subnet 2:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Subnet ID: 212.x.x.96/28&lt;/LI&gt;&lt;LI&gt;Default Gw: none&lt;/LI&gt;&lt;LI&gt;the whole host range can be assigned to the firewall, that is 212.x.x.97 - 212.x.x.110&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On our old firewall we had the 2nd subnet assigned to a DMZ zone. The servers there had public IP addresses configured on their interfaces and the firewall routed the traffic between Subnet 1 and 2. Now with the new firewall we changed that. The IP addresses of the 2nd subnet should now be owned by the firewall and NAT to private IP addresses shall be performed where necessary. How do we configure this 2nd subnet to the PA firewall properly? In theory we can't just use the default gateway 212.x.x.5 from subnet 1 as it's in another subnet... Do we have to setup a loopback interface and assign the firewall one IP address like 212.x.x.97/28 so it can perform proper routing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2012 06:45:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-ips-with-two-isps/m-p/45177#M33194</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-08-29T06:45:19Z</dc:date>
    </item>
  </channel>
</rss>

