<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inter-VR-Routing from Branch Office in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191947#M57732</link>
    <description>&lt;P&gt;Glad you have it working.&amp;nbsp; Basically you only need to create VR instances when routing separation is needed for traffic.&amp;nbsp; For internal routes like this that would rarely be the case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you did have multiple paths back for the internal traffic OSPF can be a convenient way to have the routes failover between the connections, especially when they are VPN tunnels.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 16 Dec 2017 17:56:50 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2017-12-16T17:56:50Z</dc:date>
    <item>
      <title>Inter-VR-Routing from Branch Office</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191313#M57644</link>
      <description>&lt;P&gt;Hey all!&lt;BR /&gt;&lt;BR /&gt;I am working on a Inter-VR Routing issue and would ask you for some input, how's a best practise..&lt;BR /&gt;&lt;BR /&gt;In Headquarter we have two VR's (2 Internet Routers), to reach the old official IP's there was build a DMZ2, which is in the secoundary VR ISP2. With the route in the default VR, which i say the /24-Network in this VR goes in Next Hop to VR ISP2 i can reach everything from headquarter.&lt;BR /&gt;&lt;BR /&gt;Now i want it reachable from a branch office, is it enough to make a route to the IPSec-Tunnel, or would you do this at another way? (and surely i need the policies in the specific zones from branch office to DMZ2)&lt;BR /&gt;&lt;BR /&gt;I'm very glad for your input &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; - here is a picture, i try to come from right side (Branch office) and try to reach DMZ two in HQ.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="routing_rudolstadt.gif" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12961i6E1741613DCC1183/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="routing_rudolstadt.gif" alt="routing_rudolstadt.gif" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 12:44:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191313#M57644</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-12-12T12:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VR-Routing from Branch Office</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191325#M57646</link>
      <description>&lt;P&gt;When workstations at the branch go to access services in DMZ2 what ip address will the urls resolve to?&lt;/P&gt;&lt;P&gt;Will they get these internal ip addresses or the public ip addresses using NAT on the PA3020?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If they get the internal address for the resources, then I think sending this accross the VPN is the best approach.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 13:56:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191325#M57646</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-12-12T13:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VR-Routing from Branch Office</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191326#M57647</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hey, thanks for answer.&lt;/P&gt;&lt;P&gt;they get these internal ip addresses...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i'll try to make the static route in the tunnel, i'm just not sure then to come to the secound VR with it or if i forgett something in this case (and if its workiong with the higher metric for the same route in the tunneL) ..so many questions &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and aswell, i'm thinking about enable the OSPF in the secound vr too&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 14:01:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191326#M57647</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-12-12T14:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VR-Routing from Branch Office</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191342#M57651</link>
      <description>&lt;P&gt;OK it just works with the simple static route inside the vpn tunnel &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191342#M57651</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-12-12T15:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VR-Routing from Branch Office</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191947#M57732</link>
      <description>&lt;P&gt;Glad you have it working.&amp;nbsp; Basically you only need to create VR instances when routing separation is needed for traffic.&amp;nbsp; For internal routes like this that would rarely be the case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you did have multiple paths back for the internal traffic OSPF can be a convenient way to have the routes failover between the connections, especially when they are VPN tunnels.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Dec 2017 17:56:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inter-vr-routing-from-branch-office/m-p/191947#M57732</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-12-16T17:56:50Z</dc:date>
    </item>
  </channel>
</rss>

