<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Tunnels between two PA over an MPLS infrastructure in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/184534#M56585</link>
    <description>&lt;P&gt;I have a scenario where I'm creating a VPN tunnel between two PAs. The infrastructure between the two PA is MPLS, each PA has two BGP links (Primary 50Mbps) and (Secondary 10Mbps). I'm terminating the VPN on the loopback of the PAs, however, i noticed that the VPN tunnel is initiated from the primary link (50Mbps) of the first PA and entering the second PA through Secondary Link (10Mbps). Using the BGP Import I made the primary neighbor&amp;nbsp;with local preference and weight 110 and the secondary neighbor with local preference and weight 90. I thought this will force the VPN tunnel to use the primary links from both sides but it seems not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Advice?&lt;/P&gt;</description>
    <pubDate>Mon, 30 Oct 2017 17:41:24 GMT</pubDate>
    <dc:creator>SecurityConsultant</dc:creator>
    <dc:date>2017-10-30T17:41:24Z</dc:date>
    <item>
      <title>VPN Tunnels between two PA over an MPLS infrastructure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/184534#M56585</link>
      <description>&lt;P&gt;I have a scenario where I'm creating a VPN tunnel between two PAs. The infrastructure between the two PA is MPLS, each PA has two BGP links (Primary 50Mbps) and (Secondary 10Mbps). I'm terminating the VPN on the loopback of the PAs, however, i noticed that the VPN tunnel is initiated from the primary link (50Mbps) of the first PA and entering the second PA through Secondary Link (10Mbps). Using the BGP Import I made the primary neighbor&amp;nbsp;with local preference and weight 110 and the secondary neighbor with local preference and weight 90. I thought this will force the VPN tunnel to use the primary links from both sides but it seems not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Advice?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 17:41:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/184534#M56585</guid>
      <dc:creator>SecurityConsultant</dc:creator>
      <dc:date>2017-10-30T17:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Tunnels between two PA over an MPLS infrastructure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/184699#M56617</link>
      <description>&lt;P&gt;With this config you are only controlling the &lt;EM&gt;outgoing&lt;/EM&gt; interface of each PA. This will not affect the &lt;EM&gt;incoming&lt;/EM&gt; interface on the other side (assuming both links connect to the same provider and MPLS cloud).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will want to prepend your advertisements out the secondary links to make sure incoming traffic is not received on them.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 12:30:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/184699#M56617</guid>
      <dc:creator>9t89m8fu</dc:creator>
      <dc:date>2017-10-31T12:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Tunnels between two PA over an MPLS infrastructure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/184718#M56622</link>
      <description>&lt;P&gt;thanks for your reply,&lt;/P&gt;&lt;P&gt;I really didn't get what do you mean exactly, can you explain how to do this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 12:53:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/184718#M56622</guid>
      <dc:creator>SecurityConsultant</dc:creator>
      <dc:date>2017-10-31T12:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Tunnels between two PA over an MPLS infrastructure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/184785#M56633</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In the past I have had sites with multiple lines. What I did was to use OSPF between the two VPN endpoints with static routes and policy based forwarding.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/policy/use-case-pbf-for-outbound-access-with-dual-isps" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/policy/use-case-pbf-for-outbound-access-with-dual-isps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if you have furher questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 18:55:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/184785#M56633</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-31T18:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Tunnels between two PA over an MPLS infrastructure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/185140#M56681</link>
      <description>&lt;P&gt;The solution was to use the wight to force the outgoing traffic to use the primary link by giving higher weight to the primary and to use MED to force the incoming traffic to use the primary interface by giving it lower MED.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 13:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnels-between-two-pa-over-an-mpls-infrastructure/m-p/185140#M56681</guid>
      <dc:creator>SecurityConsultant</dc:creator>
      <dc:date>2017-11-02T13:35:07Z</dc:date>
    </item>
  </channel>
</rss>

