<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dual ISP Global Protect Redundancy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-global-protect-redundancy/m-p/126870#M46562</link>
    <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hope ye all are well. We recently worked a case for a customer that had dual ISP configuration and wanted the Palo Alto Networks device to provide redundancy for the Global Protect Portal and Gateways in the event one ISP went down. We came up with a handy way of providing this using NAT rules and a loopback and I am posting this to share with the community.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are some screenshots from the lab below. Eth1/1 &amp;amp; Eth1/2 represent ISP-A and ISP-B.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="interfaces.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6410i101E313C60614853/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="interfaces.PNG" alt="interfaces.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We popped the Global Protect Portal and Gateway on a loopback interface. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="loopback.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6411iF15BDAE329D74250/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="loopback.PNG" alt="loopback.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We created two NAT rules to bounce the incoming traffic whether its from ISP-A or ISP-B to the loopback address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="natRules.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6412i29C4F6A3B16EB014/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="natRules.PNG" alt="natRules.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The system has two Virtual Routers for both ISP's. VR-A and VR-B. VR-A has the loopback interface added.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="VirtualRouters.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6413i84434F3A44A99B74/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="VirtualRouters.PNG" alt="VirtualRouters.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Virtual Router B has a static route to VR-A which has a route to the loopback interface with the Portal and Gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="VR-b-static.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6414iD362A1FC37F55F16/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="VR-b-static.PNG" alt="VR-b-static.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This simple setup allows access to the portal and gateway from either ISP interfaces. We simulated one ISP failing and changed the A record of the portal fqdn to resolve to the other interface and the users could connect without any input or changes from the end user. There are a number of ways to automate dns integrity and failover to resolve to a different ip address if it can't resolve to another. Beyond the scope of Palo Alto. Infoblox and Route 53 can provide these features. If you just have MS server , changing the A record from one IP to another isn't a massive task.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps few others and is nice way to provide extra layer of redundancy for networks to big to fail.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Robert D &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Nov 2016 21:48:16 GMT</pubDate>
    <dc:creator>DonohoeRobert</dc:creator>
    <dc:date>2016-11-16T21:48:16Z</dc:date>
    <item>
      <title>Dual ISP Global Protect Redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-global-protect-redundancy/m-p/126870#M46562</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hope ye all are well. We recently worked a case for a customer that had dual ISP configuration and wanted the Palo Alto Networks device to provide redundancy for the Global Protect Portal and Gateways in the event one ISP went down. We came up with a handy way of providing this using NAT rules and a loopback and I am posting this to share with the community.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are some screenshots from the lab below. Eth1/1 &amp;amp; Eth1/2 represent ISP-A and ISP-B.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="interfaces.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6410i101E313C60614853/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="interfaces.PNG" alt="interfaces.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We popped the Global Protect Portal and Gateway on a loopback interface. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="loopback.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6411iF15BDAE329D74250/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="loopback.PNG" alt="loopback.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We created two NAT rules to bounce the incoming traffic whether its from ISP-A or ISP-B to the loopback address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="natRules.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6412i29C4F6A3B16EB014/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="natRules.PNG" alt="natRules.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The system has two Virtual Routers for both ISP's. VR-A and VR-B. VR-A has the loopback interface added.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="VirtualRouters.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6413i84434F3A44A99B74/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="VirtualRouters.PNG" alt="VirtualRouters.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Virtual Router B has a static route to VR-A which has a route to the loopback interface with the Portal and Gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="VR-b-static.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6414iD362A1FC37F55F16/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="VR-b-static.PNG" alt="VR-b-static.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This simple setup allows access to the portal and gateway from either ISP interfaces. We simulated one ISP failing and changed the A record of the portal fqdn to resolve to the other interface and the users could connect without any input or changes from the end user. There are a number of ways to automate dns integrity and failover to resolve to a different ip address if it can't resolve to another. Beyond the scope of Palo Alto. Infoblox and Route 53 can provide these features. If you just have MS server , changing the A record from one IP to another isn't a massive task.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps few others and is nice way to provide extra layer of redundancy for networks to big to fail.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Robert D &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 21:48:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-global-protect-redundancy/m-p/126870#M46562</guid>
      <dc:creator>DonohoeRobert</dc:creator>
      <dc:date>2016-11-16T21:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP Global Protect Redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-global-protect-redundancy/m-p/219185#M63298</link>
      <description>&lt;P&gt;Great article &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6962"&gt;@DonohoeRobert&lt;/a&gt;. Thank you for sharing this solution! Question: Even though the Portal and Gateway configurations point to the loopback interface and the loopback interface is assigned to the Global-Protect security zone, in Tunnel Settings in Agent in Gateway configuration, did you still have to configure a tunnel interface and choose it in here? Or did you leave 'Tunnel Mode' unchecked?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tunnel_Mode.JPG" style="width: 660px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15627iFFA125B7E7948F43/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Tunnel_Mode.JPG" alt="Tunnel_Mode.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 21:18:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-global-protect-redundancy/m-p/219185#M63298</guid>
      <dc:creator>gdo3</dc:creator>
      <dc:date>2018-06-25T21:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP Global Protect Redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-global-protect-redundancy/m-p/219186#M63299</link>
      <description>&lt;P&gt;Hi Mate,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No worries at all..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ye need to create a tunnel interface here 100%. Gateway and portal on loopback interface is grand, but would enable tunnel mode as per normal as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let us know how it goes, article a little old but can mock up in the lab again if needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 21:43:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-global-protect-redundancy/m-p/219186#M63299</guid>
      <dc:creator>DonohoeRobert</dc:creator>
      <dc:date>2018-06-25T21:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP Global Protect Redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-global-protect-redundancy/m-p/519805#M107767</link>
      <description>&lt;P&gt;Hi&lt;SPAN class=""&gt; &lt;A class="" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6962" target="_self" aria-label="View Profile of DonohoeRobert"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;DonohoeRobert,&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Have you tried Redundancy for this case, you have configured only one default route(0.0.0.0/0) that belongs to Ethernet 1/1.&lt;BR /&gt;How will another interface(Ethernet1/2 ) route the traffic if Ethernet1/1 goes down?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Akash Thangavel&lt;/P&gt;
&lt;P&gt;Network Security Engineer&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 05:05:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-global-protect-redundancy/m-p/519805#M107767</guid>
      <dc:creator>AkashThangavel</dc:creator>
      <dc:date>2022-11-08T05:05:46Z</dc:date>
    </item>
  </channel>
</rss>

