<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dual ISP and returning traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-returning-traffic/m-p/119749#M45822</link>
    <description>&lt;P&gt;I have resolved like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- created a default route to ISP1 (usuale way in the Virtual route).&lt;/P&gt;&lt;P&gt;- removed ISP2 as second default route with higher metric&lt;/P&gt;&lt;P&gt;- added PBF to force traffic from lan to ISP2, and negate routing to internal networks (so only traffic to 0.0.0.0/0 would be intercepted).&lt;/P&gt;&lt;P&gt;- This kept ISP1 accessible while forcing traffic originating from LAN to ISP2. (and ISP2 is still accessible somehow)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very akward way to achieve a working configuration in such scenario, but thats it.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Oct 2016 06:00:31 GMT</pubDate>
    <dc:creator>myrdin</dc:creator>
    <dc:date>2016-10-18T06:00:31Z</dc:date>
    <item>
      <title>Dual ISP and returning traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-returning-traffic/m-p/119728#M45821</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is the scenario:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- ISP1 : only for GlobalProtect&lt;/P&gt;&lt;P&gt;-ISP2 : only for Internet access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISP1 has distance 10 and metric 10&lt;/P&gt;&lt;P&gt;ISP2 has distance 10 and metric 15&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in this scenario the ISP1 interface responds to Global protect gateway/portal no problem. Also ISP2 pings, and i can access management through ISP2 public ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i change the metric to ISP1 to 20, ISP2 becomes primary. BUT ISP1 no longer responds to pings nor GlobalProtect nor management, nothing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It appears that returning traffic entering ISP1 go out through ISP2 no matter what if ISP2 is preferred. The other way around tho, when ISP1 is primary, traffic entering ISP2 get out ISP2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any clues?&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 03:35:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-returning-traffic/m-p/119728#M45821</guid>
      <dc:creator>myrdin</dc:creator>
      <dc:date>2016-10-18T03:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP and returning traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-returning-traffic/m-p/119749#M45822</link>
      <description>&lt;P&gt;I have resolved like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- created a default route to ISP1 (usuale way in the Virtual route).&lt;/P&gt;&lt;P&gt;- removed ISP2 as second default route with higher metric&lt;/P&gt;&lt;P&gt;- added PBF to force traffic from lan to ISP2, and negate routing to internal networks (so only traffic to 0.0.0.0/0 would be intercepted).&lt;/P&gt;&lt;P&gt;- This kept ISP1 accessible while forcing traffic originating from LAN to ISP2. (and ISP2 is still accessible somehow)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very akward way to achieve a working configuration in such scenario, but thats it.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 06:00:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-returning-traffic/m-p/119749#M45822</guid>
      <dc:creator>myrdin</dc:creator>
      <dc:date>2016-10-18T06:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP and returning traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-returning-traffic/m-p/120534#M45937</link>
      <description>&lt;P&gt;An alternative way to configure this would be to place your Global Protect ISP into a separate virtual router.&amp;nbsp; This would isloate and give this traffic their own routing table.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 12:54:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-and-returning-traffic/m-p/120534#M45937</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-10-22T12:54:23Z</dc:date>
    </item>
  </channel>
</rss>

