<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT public IP to two private IP as failover in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113525#M45218</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depend what you are looking for:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;- Use Policy Based Routing: Activ/Passiv or Activ/Activ - and you choose which traffic on which link&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/policy/create-a-policy-based-forwarding-rule" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/policy/create-a-policy-based-forwarding-rule&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;- Use Link Layer Distribution Protocol &amp;nbsp;- act like load balancing by defining two route with same weight&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/networking-features/lldp" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/networking-features/lldp&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope hep&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Sep 2016 08:53:16 GMT</pubDate>
    <dc:creator>VinceM</dc:creator>
    <dc:date>2016-09-15T08:53:16Z</dc:date>
    <item>
      <title>NAT public IP to two private IP as failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113424#M45208</link>
      <description>&lt;P&gt;Is there a way in Palo alto firewall to do that? is some one already using it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;x.x.x.x (public) ------ Palo Alto (NAT) ----------------172.16.5.5 (primary)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;172.16.5.6 (backup)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 20:56:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113424#M45208</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-09-14T20:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: NAT public IP to two private IP as failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113433#M45209</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Should like a load balancer would work better. But thinking about it, I wonder if Policy Based Forwarding with a Monitor would work. While I have not tried it in this fashion, I have used it for a multiple ISP failover scenario.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perhaps someone else has tried it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 22:11:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113433#M45209</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2016-09-14T22:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: NAT public IP to two private IP as failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113436#M45210</link>
      <description>&lt;P&gt;I was thinking about PBF option as well but as you stated it is actually for vice versa&amp;nbsp;option as you can only specify&amp;nbsp;one &amp;nbsp;default gateway for the client in the "trust" zone. Just thinking how the client is going to change a DG if one link is failing. No VRRP option available or possible here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; One device so not much what we can do. Thinking about this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-LACP/ta-p/65837" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-LACP/ta-p/65837&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But l am not very familiar with this protocol and if it works in Layer 3 with one IP, so cannot comment much&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 23:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113436#M45210</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-09-14T23:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: NAT public IP to two private IP as failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113525#M45218</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depend what you are looking for:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;- Use Policy Based Routing: Activ/Passiv or Activ/Activ - and you choose which traffic on which link&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/policy/create-a-policy-based-forwarding-rule" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/policy/create-a-policy-based-forwarding-rule&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;- Use Link Layer Distribution Protocol &amp;nbsp;- act like load balancing by defining two route with same weight&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/networking-features/lldp" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/networking-features/lldp&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope hep&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 08:53:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113525#M45218</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2016-09-15T08:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: NAT public IP to two private IP as failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113571#M45229</link>
      <description>&lt;P&gt;you don't need to set a default gateway for the internal subnets, a simple subnet route will suffice: Policy Based Forwarding bypasses route lookups when it is active for a session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;from the perspective of the pbf configuration the public side can be treated as the local network and the 2 routes as the dual-isp&lt;/P&gt;
&lt;P&gt;-set a pbf with monitor pointed at the primary link&lt;/P&gt;
&lt;P&gt;-set a normal route to the secondary link&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 11:54:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113571#M45229</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-09-15T11:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: NAT public IP to two private IP as failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113728#M45241</link>
      <description>&lt;P&gt;just confused, do I create two NAT rules from trust to untrust as bidirectional and then apply pbf for a connected subnet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using lvl3 interfaces&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 18:04:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113728#M45241</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-09-15T18:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: NAT public IP to two private IP as failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113929#M45261</link>
      <description>&lt;P&gt;since NAT rules are zone based, you can et the external zone to zone1 and the 2 internal interfaces to zone2, that way your NAT rule will always apply, regardless of the internal interface in use&lt;/P&gt;
&lt;P&gt;then have pbf route traffic to the primary link if the monitor is up, and a static route be backup for the secondary link if the pbf monitor fails&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- During the failover from the primary interface to the backup, existing sessions will fail out due to them being bound to the interfaces, but the new sessions will simply pick up as expected, using the same NAT rule&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 21:07:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-public-ip-to-two-private-ip-as-failover/m-p/113929#M45261</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-09-16T21:07:23Z</dc:date>
    </item>
  </channel>
</rss>

