<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure second ISP with failover and aggregation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210000#M61357</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79471"&gt;@feelgood&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Theres several different approaches depending on your needs, do you simply want to have outbound connections maximally utilize all available bandwidth or do you need specific services to use a preferred route, or have one line as hot standby, have vpn redundancy, etc...&lt;/P&gt;
&lt;P&gt;does each link have it's own ip or does your ISP also aggregate the links?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The simplest setup is to setup both links equally and enable ECMP (in the virtual router), this will load balance traffic over both links, all you need to do is set up 2 individual NAT policies, one for each link&lt;/P&gt;</description>
    <pubDate>Fri, 13 Apr 2018 13:45:35 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-04-13T13:45:35Z</dc:date>
    <item>
      <title>Configure second ISP with failover and aggregation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/209991#M61356</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I'm newbie on Palo Alto systems an i have a question bout a configuration point.&lt;/P&gt;
&lt;P&gt;I have a PA-220 with one Internet connection (100 mbps). I have a second Internet connection from the same ISP (with the same bandwith =&amp;gt; 100 mbps).&lt;/P&gt;
&lt;P&gt;Now, I need to :&lt;/P&gt;
&lt;P&gt;Aggregate this two links in one logical link ;&lt;BR /&gt;Use failover system if one of this two links falls.&lt;BR /&gt;I did some research on Palo Alto Knowledge Base to find a documentation about that and I find this :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/networking/configure-an-aggregate-interface-group" target="_blank" rel="noopener"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/networking/configure-an-aggregate-interface-group&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-ISP-Redundancy-and-Load-Balancing/ta-p/58361" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-ISP-Redundancy-and-Load-Balancing/ta-p/58361&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Multiple-ISPs/ta-p/67831" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Multiple-ISPs/ta-p/67831&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I'm not sure if this links are correct to do what I want.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone know how should I go about setting up a viable setup for my PA-220 ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BB&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 14:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/209991#M61356</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2025-04-07T14:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Configure second ISP with failover and aggregation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210000#M61357</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79471"&gt;@feelgood&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Theres several different approaches depending on your needs, do you simply want to have outbound connections maximally utilize all available bandwidth or do you need specific services to use a preferred route, or have one line as hot standby, have vpn redundancy, etc...&lt;/P&gt;
&lt;P&gt;does each link have it's own ip or does your ISP also aggregate the links?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The simplest setup is to setup both links equally and enable ECMP (in the virtual router), this will load balance traffic over both links, all you need to do is set up 2 individual NAT policies, one for each link&lt;/P&gt;</description>
      <pubDate>Fri, 13 Apr 2018 13:45:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210000#M61357</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-04-13T13:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Configure second ISP with failover and aggregation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210005#M61358</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two differents IPs on each link, our ISP don't aggregate the links.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, to answer at your question, in first place, I need to use all available bandwidth (i.e 100 Mbps x 2 so 200 Mbps) then I want to have failover mechanism which use the backup link if my primary link falls. And, when the primary link is up, the virtual router reactive automatically this link&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course, I need all my VLAN toggle automatically on the backup link for continuity of service for my users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok for ECMP, so I need to create a second virtual router with the same configuration of my default configuration to permit a load balance traffic between this two links ? That's all ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Apr 2018 14:05:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210005#M61358</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2018-04-13T14:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Configure second ISP with failover and aggregation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210103#M61386</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79471"&gt;@feelgood&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ECMP doens't require an additional virtual router; it's a feature available within the virtual router configuration that allows Load Balancing between both of the ISP links. The link &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339" target="_blank"&gt;HERE&lt;/A&gt;&amp;nbsp;will go into how to actually configure ECMP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since ECMP is load-balancing the sessions between both of the uplinks, everything that you are looking for will work as best as it's able. You'll want to configure Path Monitoring on the route so that it actually gets taken out of action if it were to go down.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Apr 2018 20:23:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210103#M61386</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-13T20:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Configure second ISP with failover and aggregation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210183#M61405</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;, I setup ECMP on my PA-220 on my virtual router with the "How To" suggests by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;and for the moment, it works very well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I unplug my primary link on my PA-220 for test, the traffic goes automatically on my secondary link. Furthermore, I see in "Traffic Logs" of my PA-220, the load balancing between the two interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, now I'll monitor if all everything it's ok and try to configure GlobalProtect and IPSec on the second link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for your help guys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS : Do you know how I can change my pseudo display ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Apr 2018 11:46:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210183#M61405</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2018-04-14T11:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: Configure second ISP with failover and aggregation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210185#M61407</link>
      <description>Glad to hear all is working! &lt;BR /&gt;You can change your display name from the support portal profile editor: &lt;A href="https://live.paloaltonetworks.com/t5/Support-Articles/How-to-Change-Your-Community-Username-Display-Name/ta-p/58586" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Support-Articles/How-to-Change-Your-Community-Username-Display-Name/ta-p/58586&lt;/A&gt;</description>
      <pubDate>Sat, 14 Apr 2018 17:21:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/210185#M61407</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-04-14T17:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Configure second ISP with failover and aggregation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/1225845#M123890</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;AFAIR the problem with the ECMP implementation is, that Incoming DNAT's aren't working as intended any more, since the incoming essions are also diced in the ECMP manor, so only half of the packtes are routeted through the correct WAN Interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or is this issue solves in the meantime?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remember, in the real world you often deal with two different ISPs which discard martian ip addresses, as we don't live in the 1990ies any more &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for clearyying.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 14:04:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-second-isp-with-failover-and-aggregation/m-p/1225845#M123890</guid>
      <dc:creator>4920441</dc:creator>
      <dc:date>2025-04-07T14:04:27Z</dc:date>
    </item>
  </channel>
</rss>

