<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect\MPLS redundancy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/135065#M47452</link>
    <description>&lt;P&gt;Currently I have an MPLS connection (Connected to a Palo Alto Firewall) at one of our branch offices in Shanghai. The problem is the MPLS connection (provided by Level3) goes down sometimes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like to setup a Global Satellite connection on the PAN Firewall, with the idea being that if the MPLS goes down, we do not lose our connection to the office.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to setup the PAN to automatically start using the Global Satellite if the interface that the MPLS is connected to stops responding?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Dec 2016 18:42:01 GMT</pubDate>
    <dc:creator>mksherman</dc:creator>
    <dc:date>2016-12-29T18:42:01Z</dc:date>
    <item>
      <title>Global Protect\MPLS redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/135065#M47452</link>
      <description>&lt;P&gt;Currently I have an MPLS connection (Connected to a Palo Alto Firewall) at one of our branch offices in Shanghai. The problem is the MPLS connection (provided by Level3) goes down sometimes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like to setup a Global Satellite connection on the PAN Firewall, with the idea being that if the MPLS goes down, we do not lose our connection to the office.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to setup the PAN to automatically start using the Global Satellite if the interface that the MPLS is connected to stops responding?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2016 18:42:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/135065#M47452</guid>
      <dc:creator>mksherman</dc:creator>
      <dc:date>2016-12-29T18:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect\MPLS redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/135086#M47454</link>
      <description>&lt;P&gt;You mean a GlobalProtect LSVPN sattelite or an actual Satellite internet connection? Either one can be done pretty easily but if you lose your MPLS connection would that not mean that the office also losses their internet connection or are you using the MPLS similar to a split-tunnel?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2016 20:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/135086#M47454</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-29T20:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect\MPLS redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/135098#M47456</link>
      <description>&lt;P&gt;I mean a Satellite connection seen here: &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Satellite/ta-p/59056" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Satellite/ta-p/59056&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our MPLS is a separate circuit from our Internet connection. If we lose our MPLS the office still has an internet connection. What I've been doing as a work around for now is that, if the MPLS goes down I have them connect to a "guest wifi" that is only connected to the internet and use the Global Protect Client to VPN in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2016 21:38:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/135098#M47456</guid>
      <dc:creator>mksherman</dc:creator>
      <dc:date>2016-12-29T21:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect\MPLS redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/135637#M47532</link>
      <description>&lt;P&gt;Global protect satellite doesn't provide redundancy. PBF or dynamic routing do.&lt;/P&gt;&lt;P&gt;Since you'll have 2 links: MPLS and VPN, you can simply configure PBF to use your primary link (MPLS) which be failing over to your VPN (static route) in case it fails&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Selecting-an-IP-Address-for-PBF-or-Tunnel-Monitoring/ta-p/61993" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Selecting-an-IP-Address-for-PBF-or-Tunnel-Monitoring/ta-p/61993&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gerardo.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 21:43:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/135637#M47532</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2017-01-03T21:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect\MPLS redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/136309#M47616</link>
      <description>&lt;P&gt;Old setup:&lt;/P&gt;&lt;P&gt;Our trust interface (1/3) in Shanghai is setup with a static IP of 10.51.1.1/24 and as layer3.&lt;/P&gt;&lt;P&gt;Connected to the trust interface is a dumb switch and connected to the switch is 10 workstations.&lt;/P&gt;&lt;P&gt;The workstations are getting DHCP from the 1/3 interface which I've enabled on the PAN with the gateway set to 10.51.1.1&lt;/P&gt;&lt;P&gt;There's a static route saying anything on 10.0.0.0/8 go out ethernet 1/2 (our MPLS) with IP 192.168.1.51&lt;/P&gt;&lt;P&gt;*Once the MPLS hits our headquarters there's a static route on our switches that says:&lt;/P&gt;&lt;P&gt;192.168.1.X/29 via our MPLS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New setup:&lt;/P&gt;&lt;P&gt;Everything from before will be the same but I want to add a GlobalSattelite connection in case the MPLS next hop goes down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup Question:&lt;/P&gt;&lt;P&gt;If I set up the Satellite connection to share the route for 10.51.1.0/24 will I cause a loop?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2017 21:08:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mpls-redundancy/m-p/136309#M47616</guid>
      <dc:creator>mksherman</dc:creator>
      <dc:date>2017-01-06T21:08:41Z</dc:date>
    </item>
  </channel>
</rss>

