<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN failover with Dual ISP with single VR &amp;amp; single Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200665#M59335</link>
    <description>&lt;P&gt;for you to be able to make an outbound ipsec connection ,you need to initiate a connection from you rsystem out to the internet&lt;/P&gt;
&lt;P&gt;for your packets to reach their final destination ,a route lookup needs to occur an d a routing decission to which interface your packets should egrtess out of&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you only have 1 VR, only 1 default route can be active so both your tunnels will egress out of the same interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are able to add host routes you could try to point each tunnel's destination IP out of a different interface, this could allow for a single VR setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are not able to add a host route (if your ISP assigns you a dynamic IP for example) you will need to rely on the default route. In this case, you will need an additional VR so each ISP can have it's own default route and each tunnel will only be active on the VR with the preferred ISP's default route&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Feb 2018 13:48:09 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-02-15T13:48:09Z</dc:date>
    <item>
      <title>VPN failover with Dual ISP with single VR &amp; single Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200654#M59330</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Below link explains about vpn failover with dual isp and dual vr, but cant I use same VR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why its mandtory to use two VR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with regards,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 12:35:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200654#M59330</guid>
      <dc:creator>RamBalaji</dc:creator>
      <dc:date>2018-02-15T12:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover with Dual ISP with single VR &amp; single Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200661#M59331</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78551"&gt;@RamBalaji&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dual VR is optimal so you have 2 default routes so each IPSEC connection has a unique route out (else yuou can only have 1 default gateway and both tunnels would go out of the same interface)&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 12:52:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200661#M59331</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-15T12:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover with Dual ISP with single VR &amp; single Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200663#M59333</link>
      <description>&lt;P&gt;Can you please explain in detail i couldn't understand..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with regards,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 13:25:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200663#M59333</guid>
      <dc:creator>RamBalaji</dc:creator>
      <dc:date>2018-02-15T13:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover with Dual ISP with single VR &amp; single Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200665#M59335</link>
      <description>&lt;P&gt;for you to be able to make an outbound ipsec connection ,you need to initiate a connection from you rsystem out to the internet&lt;/P&gt;
&lt;P&gt;for your packets to reach their final destination ,a route lookup needs to occur an d a routing decission to which interface your packets should egrtess out of&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you only have 1 VR, only 1 default route can be active so both your tunnels will egress out of the same interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are able to add host routes you could try to point each tunnel's destination IP out of a different interface, this could allow for a single VR setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are not able to add a host route (if your ISP assigns you a dynamic IP for example) you will need to rely on the default route. In this case, you will need an additional VR so each ISP can have it's own default route and each tunnel will only be active on the VR with the preferred ISP's default route&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 13:48:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200665#M59335</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-15T13:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover with Dual ISP with single VR &amp; single Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200697#M59344</link>
      <description>&lt;P&gt;What if I did it this way?&lt;BR /&gt;1 VR, First peer public IP reached via default route&amp;nbsp;via ISP1. Second peer public IP reached via /32 static route pointing to ISP2.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 14:55:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200697#M59344</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-02-15T14:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover with Dual ISP with single VR &amp; single Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200703#M59347</link>
      <description>&lt;P&gt;That should work&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 15:08:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200703#M59347</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-15T15:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover with Dual ISP with single VR &amp; single Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200704#M59348</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes this can work. I have set it up multiple times over the years. Then I either use a Policy Based Forwarding rule or OSPF weights to determine which path I want to use as primary and secondary, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 15:09:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/200704#M59348</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-15T15:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover with Dual ISP with single VR &amp; single Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/353146#M87283</link>
      <description>&lt;P&gt;How about if i did it this way,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 VR, First peer public IP reached via default route via isp1, Same Peer Public IP reached via PBF Pointing to ISP2 ( Condition of Source Address for Tunnel&amp;nbsp; and Destination of same Peer IP )&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 21:33:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/353146#M87283</guid>
      <dc:creator>m7usman</dc:creator>
      <dc:date>2020-09-30T21:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover with Dual ISP with single VR &amp; single Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/447115#M100654</link>
      <description>&lt;P&gt;to confirm this is not possible with single VR going to same public IP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have VPN 1 - going through unique public IP to branch public IP&lt;/P&gt;&lt;P&gt;I have VPN 2 - going through unique public IP to same branch public IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the same VR. To confirm this is not possible? I tried to move to dual VR but i caused a ton of routing issues and I had to revert. Will try dual VR set up again if its the only way possible.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 02:25:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-failover-with-dual-isp-with-single-vr-amp-single-firewall/m-p/447115#M100654</guid>
      <dc:creator>jmcrae</dc:creator>
      <dc:date>2021-11-12T02:25:50Z</dc:date>
    </item>
  </channel>
</rss>

