<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dual ISP scenario in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206906#M60686</link>
    <description>&lt;P&gt;Thanks reaper. Outbound is ok.&lt;/P&gt;&lt;P&gt;Thinking in inboud:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have these NAT rules:&lt;/P&gt;&lt;P&gt;ISP1 is 1.1.1.1:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, there is any way to clone all these NAT rules changing ISP 2.2.2.2, and if ISP 1.1.1.1 goes down, the inbound sessions take ISP 2???? any NAT track or way to configure public services with both ISPs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Mar 2018 15:48:48 GMT</pubDate>
    <dc:creator>soporteseguridad</dc:creator>
    <dc:date>2018-03-22T15:48:48Z</dc:date>
    <item>
      <title>Dual ISP scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206889#M60677</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to create a dual ISP scenario. This FW has 2 interface with differents ISP. (ppoe)&lt;/P&gt;&lt;P&gt;eth1/2 (1.1.1.1/32)&lt;/P&gt;&lt;P&gt;eth1/3 (2.2.2.2/32)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We&amp;nbsp;would like to balance both ISPs and in the case one of this ISP goes down, all traffic takes the ISP up in that moment. So i was checking,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also i would like to force some trust range to take interface 1/2 (using PBF), an in the case this interfaces 1/2 goes down, to take int1/3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on the another hand, there are several services on internet for this public IP. So how ca we public the NAT in both ISP interface??? clonning all the NATs using the new ISP IPs??? thats enough i think&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 14:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206889#M60677</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2018-03-22T14:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206897#M60680</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9102"&gt;@soporteseguridad&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;outbound you would be ok with ECMP and using PBF policies to force certain traffic onto a specific interface&lt;/P&gt;
&lt;P&gt;outbound NAT would simply be regular outbound hide-NAT with a destination interface set and source NAT to the proper ISP subnet (clone and change destination interface + source translation)&lt;/P&gt;
&lt;P&gt;Inbound NAT will only work for the ISP that routes the public IP so this can only be configured once for the appropriate ISP (so no cloning here)&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 14:08:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206897#M60680</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-22T14:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206906#M60686</link>
      <description>&lt;P&gt;Thanks reaper. Outbound is ok.&lt;/P&gt;&lt;P&gt;Thinking in inboud:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have these NAT rules:&lt;/P&gt;&lt;P&gt;ISP1 is 1.1.1.1:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, there is any way to clone all these NAT rules changing ISP 2.2.2.2, and if ISP 1.1.1.1 goes down, the inbound sessions take ISP 2???? any NAT track or way to configure public services with both ISPs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 15:48:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206906#M60686</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2018-03-22T15:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206909#M60688</link>
      <description>&lt;P&gt;Forget inbound, we would have DNS problem, and create abother zone for ISP2.......to many config fo this end customer.....&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks a lot reaper&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 15:03:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206909#M60688</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2018-03-22T15:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206912#M60690</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The only way to get inbound redirection to work would be to use an external load balancer. That way the LB would know which way is the best path and route to it while the public DNS record points to the LB IP's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 15:14:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-scenario/m-p/206912#M60690</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-22T15:14:16Z</dc:date>
    </item>
  </channel>
</rss>

