<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec tunnel as backup link of MPLS connection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-as-backup-link-of-mpls-connection/m-p/5694#M4165</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think you should use PBF for this since only by using PBF you can achieve automatic failover. Unless you have a dynamic routing protocol running in your MPLS networks, there is no way that the firewall knows that the route to your MPLS cloud was down.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Nov 2013 10:56:30 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-11-27T10:56:30Z</dc:date>
    <item>
      <title>IPSec tunnel as backup link of MPLS connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-as-backup-link-of-mpls-connection/m-p/5693#M4164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have MPLS link between two sites. Right now I want to setup backup link with IPSec tunnel. schema of network connection is as on picture.&lt;/P&gt;&lt;P&gt;please help me to configure Palo Alto device to monitor MPLS link and switch to IPSec tunnel when MPLS link will be down.&lt;/P&gt;&lt;P&gt;Switch on right site has IPSLA ready that check connection to MPLS router and change routing automatically to PA. &lt;/P&gt;&lt;P&gt;Palo Alto has two routing record for the same sub net with different metric and adm distance but it don't swap to IPSec automatically. Please tell me how I should configure PA to support this scenario without my interaction ?&lt;/P&gt;&lt;P&gt;What should I use PBF, redistribution profiles under VR - static, add one VR more, Monitor tunnel?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Visio-pa_mpls_Ipsec.jpg" class="jive-image-thumbnail jive-image" height="384" src="https://live.paloaltonetworks.com/legacyfs/online/5700_Visio-pa_mpls_Ipsec.jpg" width="544" /&gt;&lt;/P&gt;&lt;P&gt;Thank you for advice!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2013 11:42:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-as-backup-link-of-mpls-connection/m-p/5693#M4164</guid>
      <dc:creator>jakub_gniazdowski</dc:creator>
      <dc:date>2013-02-22T11:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel as backup link of MPLS connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-as-backup-link-of-mpls-connection/m-p/5694#M4165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think you should use PBF for this since only by using PBF you can achieve automatic failover. Unless you have a dynamic routing protocol running in your MPLS networks, there is no way that the firewall knows that the route to your MPLS cloud was down.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 10:56:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-as-backup-link-of-mpls-connection/m-p/5694#M4165</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-11-27T10:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel as backup link of MPLS connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-as-backup-link-of-mpls-connection/m-p/5695#M4166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jakub,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes we will have to use PBF to have auto failover if the primary link is failed.&lt;/P&gt;&lt;P&gt;In PBF rule we set the primary link ( in your case it is MPLS path ). PBF rules are given priority over default routes and security rules. If the PBF fails then it would take the default static route to the tunnel for backup path.&lt;/P&gt;&lt;P&gt;Below are some doc suggestions to understand and customize your implementation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4500"&gt;How to Setup a Palo Alto Networks Firewall with Dual ISPs and Automatic VPN Failover&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1357"&gt;Dual ISP Branch Office Configuration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 12:41:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-as-backup-link-of-mpls-connection/m-p/5695#M4166</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-11-27T12:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel as backup link of MPLS connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-as-backup-link-of-mpls-connection/m-p/5696#M4167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fully agree with Phoenix. Just be sure that the juniper on remote site be able to send traffic in VPN too (in case of vpn failure) alse ... it will fail &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;v.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 19:01:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-as-backup-link-of-mpls-connection/m-p/5696#M4167</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-11-27T19:01:02Z</dc:date>
    </item>
  </channel>
</rss>

