<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring profile troubles - Dual ISP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-profile-troubles-dual-isp/m-p/8953#M41280</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any new info on this one?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Jul 2015 18:06:50 GMT</pubDate>
    <dc:creator>treese</dc:creator>
    <dc:date>2015-07-28T18:06:50Z</dc:date>
    <item>
      <title>Monitoring profile troubles - Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-profile-troubles-dual-isp/m-p/8952#M41279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got a TAC with PA opened for this one but wanted to ask the community if you've experience this one.&amp;nbsp; The problem is when the PBF kicks in (disabled primary circuit) the primary circuit traffic immediately fails over to the backup ISP.&amp;nbsp; I've adjusted the fail-over monitoring profile interval's and the threshold but neither seem to have an affect.&amp;nbsp; Its basically working like a floating static route which I'm wanting to avoid.&amp;nbsp; The plan is when the primary circuit is unavailable to wait and fail-over at a specified time - 100 sec interval would be fine.&amp;nbsp; This is how I understand it:&lt;/P&gt;&lt;P&gt;"A monitoring profile allows the user to specify the threshold number of heartbeats to determine whether the IP address is reachable" then take the action specified - wait to recover or fail-over.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anything I'm missing or suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Apr 2015 20:05:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-profile-troubles-dual-isp/m-p/8952#M41279</guid>
      <dc:creator>treese</dc:creator>
      <dc:date>2015-04-24T20:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring profile troubles - Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-profile-troubles-dual-isp/m-p/8953#M41280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any new info on this one?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jul 2015 18:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-profile-troubles-dual-isp/m-p/8953#M41280</guid>
      <dc:creator>treese</dc:creator>
      <dc:date>2015-07-28T18:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring profile troubles - Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-profile-troubles-dual-isp/m-p/72959#M41285</link>
      <description>&lt;P&gt;How are you doing the failover testing? Are you pulling the link or killing the interface on the connected switch? If that's how you're testing, the failover will be immediate because the link is effectively dead. There's no hold timer because the routes are immediately removed from the route table.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're monitoriting a remote IP, try denying that IP with an upstream firewall or ACL, or by blocking your primary ISPs public interface address from your monitor server. This should induce the failure in a way that would mimic an outage on the ISP side without actually updating the route table immediately.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are already doing it the 2nd way above, then I would expect it to work using the hold timer you've configured. Anything other than that would probably be best troubleshot with a support case. You can also take a look at your routing tables with "show routing route" on the firewall's CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2016 05:18:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-profile-troubles-dual-isp/m-p/72959#M41285</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2016-02-17T05:18:48Z</dc:date>
    </item>
  </channel>
</rss>

