<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static Route Removal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212297#M61923</link>
    <description>&lt;P&gt;Do you have separate interfaces connected to ISP-A and B?&lt;/P&gt;&lt;P&gt;How are your static routes configured? Sounds like path monitoring. What are you using for source interfaces on each route?&lt;/P&gt;&lt;P&gt;What is the metric configuration on each route?&lt;/P&gt;</description>
    <pubDate>Mon, 30 Apr 2018 16:22:30 GMT</pubDate>
    <dc:creator>rmfalconer</dc:creator>
    <dc:date>2018-04-30T16:22:30Z</dc:date>
    <item>
      <title>Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212218#M61908</link>
      <description>&lt;P&gt;Default route via ISP-A (primary) has not yet recovered, even though the monitored IP address (DNS server of ISP-A) is already rechable via the interface connected to ISP-A router. (tested via ping source x.x.x.x&amp;nbsp;host y.y.y.y)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen the logs from previous months that the firewall has detected path failure and was able to recover.&amp;nbsp;So I assume the setup is correct?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Any other troubleshooting that I can do? Or any other things to double check on my setup?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Apr 2018 14:35:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212218#M61908</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-04-29T14:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212234#M61909</link>
      <description>&lt;P&gt;Update on this.&lt;/P&gt;&lt;P&gt;Current routing table is still via ISP-B.&lt;BR /&gt;Upon using traceroute source x.x.x.x host y.y.y.y, I saw that the DNS Server of ISP-A is being reached via ISP-B.&lt;/P&gt;&lt;P&gt;Do I need to put a specific static route pointing to DNS Server of ISP-A via ISP-A gateway?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 06:31:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212234#M61909</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-04-30T06:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212297#M61923</link>
      <description>&lt;P&gt;Do you have separate interfaces connected to ISP-A and B?&lt;/P&gt;&lt;P&gt;How are your static routes configured? Sounds like path monitoring. What are you using for source interfaces on each route?&lt;/P&gt;&lt;P&gt;What is the metric configuration on each route?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 16:22:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212297#M61923</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-04-30T16:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212354#M61930</link>
      <description>&lt;P&gt;if you are monitoring ISP A , then yes, the route for the tracking of that DNS(A) would have to be forced through ISP A only using the static routes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;~HTH&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 20:16:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212354#M61930</guid>
      <dc:creator>Harshit</dc:creator>
      <dc:date>2018-04-30T20:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212363#M61932</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;You can also specify the interface. Hopefully each ISP has their own?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 21:27:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212363#M61932</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-04-30T21:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212381#M61936</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's my setup.&lt;/P&gt;&lt;P&gt;ISPA (eth1/1) and LAN interfaces on one VR1&lt;/P&gt;&lt;P&gt;ISPB (eth1/2) on another VR2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VR1 Routes:&lt;/P&gt;&lt;P&gt;-Default route&amp;nbsp; (defaul admin distance, metric 10) w/ path monitoring (Monitored IP - DNS of ISP-A, source eth1/1, other settings default)&lt;/P&gt;&lt;P&gt;-Backup default route to next VR (default admin distance, metric 20)&lt;/P&gt;&lt;P&gt;-Specific /32 route of DNS of ISP-A to force it via ISP-A Gateway.&lt;/P&gt;&lt;P&gt;-Tunnel Routes&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;VR2 Routes:&lt;BR /&gt;-Defaul route pointing to ISPB gateway&lt;/P&gt;&lt;P&gt;-Return routes to LAN segments (via next VR1)&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 07:09:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212381#M61936</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-05-01T07:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212382#M61937</link>
      <description>&lt;P&gt;I just added the specific /32 route going to DNS os ISP-A via the ISP-A Gateway.&lt;/P&gt;&lt;P&gt;ping source eth1/1 (ISP-A port) host DNS of ISPA, fails now.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 07:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212382#M61937</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-05-01T07:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212399#M61938</link>
      <description>&lt;P&gt;Update:&lt;BR /&gt;&lt;BR /&gt;Stand-alone test worked fine.&lt;BR /&gt;Can reach the internet and the DNS of ISPA (monitored IP in path monitoring of default route)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I guess the problem is on the PA? Anything that I need to double check?&lt;BR /&gt;Checking from previous logs, firewall was able to detect path failure and was also able to recover.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 11:06:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212399#M61938</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-05-01T11:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212416#M61943</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Do you have any dynamic routing between the VR's? Perhaps that is how it learned the routes? But sounds like you have it solved with the static /32 routes. I also use them to be super specific on certain destinations for monitring and dynamic routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 14:02:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212416#M61943</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-01T14:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212418#M61944</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No Dynamic Routes between VR's.&lt;/P&gt;&lt;P&gt;Adding the specific /32 static route did not resolve the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Path Monitoring status is stil down.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 14:06:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212418#M61944</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-05-01T14:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212419#M61945</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Sorry I misread that. when you do the ping, do the traffic logs show anything useful or is the traffic allowed? Also is ISP A in an upstate? What about the routes in the Forwarding table, are they correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/network/network-virtual-routers/more-runtime-stats-for-a-virtual-router/routing-tab" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/network/network-virtual-routers/more-runtime-stats-for-a-virtual-router/routing-tab&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two tables, the route table and forwarding table, the traffic will flow per the forwarding table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry if i missed something in an earlier post.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 14:12:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212419#M61945</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-01T14:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212424#M61947</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;no worries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port Connected to ISPA is in up state. No logs is generated as I am using the eth1/2 as the source of the ping to reach the ISP-A DNS Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Routes in the forwarding table:&lt;BR /&gt;Default Route is via next VR (ISPB VR)&lt;/P&gt;&lt;P&gt;ISP-A DNS Server via ISP-A Gateway&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 14:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212424#M61947</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-05-01T14:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212425#M61948</link>
      <description>&lt;P&gt;OK,&amp;nbsp;I think I understand now.&amp;nbsp;What happens if you ping ISP A DNS from port 1/1?&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 14:35:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212425#M61948</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-01T14:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212437#M61950</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Port 1/1 - ISP B&lt;BR /&gt;Port 1/2 - ISP A&lt;BR /&gt;&lt;BR /&gt;ping 'port 1/1 IP' host 'ISP-A DNS IP' --- success&lt;/P&gt;&lt;P&gt;ping 'port 1/2 IP' host 'ISP-A DNS IP' --- fail&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 15:06:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212437#M61950</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-05-01T15:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212439#M61951</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would say double check the FIB table and traffic logs as this kinda makes sense to me, but I could be wrong. Meaning that since you have the /32 route to the DNS of ISP A, when you try to ping from the other ISP B interface, its trying to route internnally and out ISP A interface. In the VR or ISP B put in a /32 route to ISP A DNS and I bet it will reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 15:18:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212439#M61951</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-01T15:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Removal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212454#M61961</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72987"&gt;@theonewhoknocks&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;So on the interface that connects directly to ISP-A has a failure on pinging the DNS server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;If you trace from the interface connected to ISP-A to the DNS server, where does it fail?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Do you have a requirement to use separate VRs for this configuration?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 16:00:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-removal/m-p/212454#M61961</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-05-01T16:00:42Z</dc:date>
    </item>
  </channel>
</rss>

