<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question about redundent paths with IPSEC Tunnels. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-redundent-paths-with-ipsec-tunnels/m-p/189131#M57297</link>
    <description>&lt;P&gt;I have a HA-pair of 3050s in my corp office with an single existing IPSEC tunnel to a remote office on a 200.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The remote office has very poor reliability on it's existing connection and the local ISP has provided them with a backup satcom link they can use when the prime connection goes down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the HA-pair sits behind a Single IP that's managed via BGP on a HA-pair of routers with redundent internet links. The main IP will float between the routers using HSRP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it was only a matter of flipping a route on the remote 200, it wouldn't be an issue, but how do I get the tunnel to migrate from one local IP to another?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2017 16:02:47 GMT</pubDate>
    <dc:creator>cengasser</dc:creator>
    <dc:date>2017-11-29T16:02:47Z</dc:date>
    <item>
      <title>Question about redundent paths with IPSEC Tunnels.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-redundent-paths-with-ipsec-tunnels/m-p/189131#M57297</link>
      <description>&lt;P&gt;I have a HA-pair of 3050s in my corp office with an single existing IPSEC tunnel to a remote office on a 200.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The remote office has very poor reliability on it's existing connection and the local ISP has provided them with a backup satcom link they can use when the prime connection goes down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the HA-pair sits behind a Single IP that's managed via BGP on a HA-pair of routers with redundent internet links. The main IP will float between the routers using HSRP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it was only a matter of flipping a route on the remote 200, it wouldn't be an issue, but how do I get the tunnel to migrate from one local IP to another?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 16:02:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-redundent-paths-with-ipsec-tunnels/m-p/189131#M57297</guid>
      <dc:creator>cengasser</dc:creator>
      <dc:date>2017-11-29T16:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Question about redundent paths with IPSEC Tunnels.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-redundent-paths-with-ipsec-tunnels/m-p/189611#M57384</link>
      <description>&lt;P&gt;For this type of setup, I would remove the static route on the VPN tunnel.&amp;nbsp; And setup OSPF on the tunnel interfaces between the remote site and the cluster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can then have two VPN active at all times and use OSPF cost on the back link to make sure it is less preferred.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are not running OSPF currently on the HA PA, you can import these remote side routes into your BGP setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the remote side set the LAN interfaces there to passive OSPF so that their subnets get advertised up both tunnel neighbors.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2017 13:11:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-redundent-paths-with-ipsec-tunnels/m-p/189611#M57384</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-12-03T13:11:09Z</dc:date>
    </item>
  </channel>
</rss>

