<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Redundancy VPN  between two sites with two ISP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/215139#M62456</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a guide we used on our site-to-site VPN with two ISP. I just followed the guide step by step. Hope this helps you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 May 2018 06:53:13 GMT</pubDate>
    <dc:creator>theonewhoknocks</dc:creator>
    <dc:date>2018-05-23T06:53:13Z</dc:date>
    <item>
      <title>Redundancy VPN  between two sites with two ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/214999#M62427</link>
      <description>&lt;P&gt;HELLO ALL&lt;/P&gt;&lt;P&gt;We have two PA devices.(850 and 500).They are located in different sites.Both firewalls have two connections to Internet via 2 different ISPs&lt;/P&gt;&lt;P&gt;We want to make Site to Site VPN between these sites.But make it redundant.Two VPN connections between sites through different ISPs&lt;/P&gt;&lt;P&gt;I can not find any manual how one can configure this schema&lt;/P&gt;&lt;P&gt;Please post some guide if you know&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 09:44:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/214999#M62427</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-05-22T09:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Redundancy VPN  between two sites with two ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/215139#M62456</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a guide we used on our site-to-site VPN with two ISP. I just followed the guide step by step. Hope this helps you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2018 06:53:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/215139#M62456</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-05-23T06:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Redundancy VPN  between two sites with two ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/417375#M93535</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72987"&gt;@theonewhoknocks&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I think&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;&amp;nbsp;needs an instruction for dual ISP at "both" site, just like below topology.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aaa.JPG" style="width: 962px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34793i7D93764462D5E506/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="aaa.JPG" alt="aaa.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am looking for the same solution. We are using hub-spoke site-to-site VPN topology and both hub (HQ) and spoke (branch) have dual ISPs. The URL you shared seems could not be applied to dual ISP at both sites situation. Is there any other advice you could share?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 22:57:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/417375#M93535</guid>
      <dc:creator>YifengLiu</dc:creator>
      <dc:date>2021-07-06T22:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Redundancy VPN  between two sites with two ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/417565#M93568</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Here is something I have done in the past and works well. This will utilize one tunnel until there is a failure then fail over.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Using&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160979"&gt;@YifengLiu&lt;/a&gt; diagram above:&lt;UL&gt;&lt;LI&gt;setup the external ethernet interfaces for their respective ISP's&lt;/LI&gt;&lt;LI&gt;Make sure your policies allow the traffic&lt;/LI&gt;&lt;LI&gt;build first tunnel BLR-PAN eth 1/1 to AZ-PAN eth 1/1. Setup an IP address for each tunnel interface (makes troubleshooting easier)&lt;UL&gt;&lt;LI&gt;Verify traffic can flow&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Setup OSPF between the two PAN's&lt;UL&gt;&lt;LI&gt;Verify adjacency&lt;/LI&gt;&lt;LI&gt;verify route propagation&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Build the rest of the 3 VPN Tunnels:&lt;UL&gt;&lt;LI&gt;BLR-PAN eth 1/2 to AZ-PAN eth 1/1&lt;/LI&gt;&lt;LI&gt;BLR-PAN eth 1/1 to AZ-PAN eth1/2&lt;/LI&gt;&lt;LI&gt;BLR-PAN eth 1/2 to AZ-PAN eth 1/2&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Then use OSPF to regulate the priority of the tunnels if you are getting asymetric traffic issues.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;i.e.&lt;UL&gt;&lt;LI&gt;BLR-PAN eth1/1 to AZ-PAN eth 1/1 normal Metric&lt;/LI&gt;&lt;LI&gt;BLR-PAN eth 1/1 to AZ-PAN eth 1/2 metric 5000&lt;/LI&gt;&lt;LI&gt;BLR-PAN eth 1/2 to AZ-PAN eth 1/2 metric 10000&lt;/LI&gt;&lt;LI&gt;BLR-PAN eth 1/2 to AZ-PAN eth 1/1 metric 15000&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This is highly simplified but should work if one of the ISP's goes down, OSPF will reroute automatically. You can use Policy Based Forwarding for the static routes between the VPN IP's and they can disable as required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 16:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/417565#M93568</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-07-07T16:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Redundancy VPN  between two sites with two ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/417622#M93580</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;. I will need some time to verify your suggestion because currently I am using 2VRs with PBF by following this article, &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFiCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFiCAK&lt;/A&gt;. Due to it's production devices, I will not be able to test it in a short time, but your advice seems work. I just need find a time to figure out the detail configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 20:52:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/417622#M93580</guid>
      <dc:creator>YifengLiu</dc:creator>
      <dc:date>2021-07-07T20:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Redundancy VPN  between two sites with two ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/417637#M93581</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yeah I was never a huge fan of the 2 VR solution. The method I described only requires 1 VR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 21:23:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redundancy-vpn-between-two-sites-with-two-isp/m-p/417637#M93581</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-07-07T21:23:45Z</dc:date>
    </item>
  </channel>
</rss>

