<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prefer 1 ISP for one application in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prefer-1-isp-for-one-application/m-p/102499#M44568</link>
    <description>&lt;P&gt;Two suggestions: &amp;nbsp;First, don't use application as a matching criteria in PBF. &amp;nbsp;As you indicated, it needs to look at some packets before it determines the application, by which time it's too late. &amp;nbsp;Instead, just use source &amp;amp; destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, if the fix above works, then your traffic monitoring rule should see that the ISP is down and automatically switch to the second ISP.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Aug 2016 05:30:18 GMT</pubDate>
    <dc:creator>rabolfathi</dc:creator>
    <dc:date>2016-08-12T05:30:18Z</dc:date>
    <item>
      <title>How to prefer 1 ISP for one application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prefer-1-isp-for-one-application/m-p/102187#M44551</link>
      <description>&lt;P&gt;I got why huge traffic is coming to port 3978.Application is identified as Panorama.&lt;BR /&gt;Its hge Gbs of traffic in one session.&lt;BR /&gt;The source IP is firewall management Ip and destination is Panorama IP.&lt;/P&gt;&lt;P&gt;But why i need to kill this session means, we have a setup of 2 ISPs. We prefere this traffic should go through 1 ISP only one ISP.&lt;/P&gt;&lt;P&gt;Tht we accomplish through PBF ruless to 1 ISP.we use port in PBF. However there are 2 issues in this:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1) As per PBF session, first few packets will go thorgh normal routing table and wont take PBF. untill the aplication identified. in this case as it is Panorama traffc it is never ending traffic.&lt;BR /&gt;So this stayes at 1 ISP only( Not the ISP we define in PBF) . We have to manually kill Session an then next sessio will take 2 nd ISP.&lt;BR /&gt;&lt;BR /&gt;2) another scenarion, lets assume my 1st ISP down, then panorama traffic will take 2nd ISP( non prefereed). But even if 1st ISP came up also, as panorama is never ending session, it will continue on 2 nd ISP untll we clear manually.&lt;BR /&gt;&lt;BR /&gt;Can any one have suggestions on this.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2016 04:33:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prefer-1-isp-for-one-application/m-p/102187#M44551</guid>
      <dc:creator>Roby_Sreejith</dc:creator>
      <dc:date>2016-08-11T04:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to prefer 1 ISP for one application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prefer-1-isp-for-one-application/m-p/102293#M44555</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately i don't think there's an easy fix as the backend connection to panorama is kept open continuously&lt;/P&gt;
&lt;P&gt;You could try setting a static route for a single IP instead of the PBF policy for this specific issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One bit of good new may be that the traffic to panorama should not be that big: when the session ends the today bytecount is added for the complete duration of the single session, which could be weeks to even months of data all added into 1 bytecount. if you do see excessive bandwidth usage, you can opt to tone down log forwarding to only the critical logs&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2016 11:42:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prefer-1-isp-for-one-application/m-p/102293#M44555</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-08-11T11:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to prefer 1 ISP for one application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prefer-1-isp-for-one-application/m-p/102499#M44568</link>
      <description>&lt;P&gt;Two suggestions: &amp;nbsp;First, don't use application as a matching criteria in PBF. &amp;nbsp;As you indicated, it needs to look at some packets before it determines the application, by which time it's too late. &amp;nbsp;Instead, just use source &amp;amp; destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, if the fix above works, then your traffic monitoring rule should see that the ISP is down and automatically switch to the second ISP.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2016 05:30:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prefer-1-isp-for-one-application/m-p/102499#M44568</guid>
      <dc:creator>rabolfathi</dc:creator>
      <dc:date>2016-08-12T05:30:18Z</dc:date>
    </item>
  </channel>
</rss>

