<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change ISP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/219781#M63427</link>
    <description>&lt;P&gt;ISP was changed successfully...for all of the network engineers out there...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Change the interface IP&lt;/P&gt;&lt;P&gt;- Chane the default route&lt;/P&gt;&lt;P&gt;- Change GlobalProtect settings&lt;/P&gt;&lt;P&gt;- Issue a new cert. for GlobalProtect&lt;/P&gt;&lt;P&gt;- Change the polices&lt;/P&gt;&lt;P&gt;-No need to reset the VPN&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jun 2018 19:23:05 GMT</pubDate>
    <dc:creator>Si_Infrastructure</dc:creator>
    <dc:date>2018-06-28T19:23:05Z</dc:date>
    <item>
      <title>Change ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/217299#M62873</link>
      <description>&lt;P&gt;we're upgrading the internet link in one of our offices...so qwe purchased a new link from a different provider...and I was thinking of unplugging the old link, plugin the new link, remove the old public IP address and then add the IP address of the new link, change the default route...the firewall is PA-200 version&amp;nbsp;&lt;SPAN&gt;7.1.14...has anyone done this before? is this a good practise?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jun 2018 18:44:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/217299#M62873</guid>
      <dc:creator>Si_Infrastructure</dc:creator>
      <dc:date>2018-06-10T18:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/217322#M62877</link>
      <description>&lt;P&gt;If you have a maintenance window where you can perform a cutover, this would be a good way to go about your migration (don't forget NAT and security policies)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will be the quickest way, but will require some downtime (and you'll need to make sure you have OOB acccess or can be on-site to perform this)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;alternatively you can plug the new ISP in a free interface and set it up from scratch (new zone, add the sone to existing security policies, create new NAT rules, add default route with slightly higher metric and commit)&lt;/P&gt;
&lt;P&gt;after the commit you can first run a few tests and will retain access to the office through the original ISP, until you shut off the original interface and the NEW ISP will take over&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 09:26:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/217322#M62877</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-06-11T09:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/217348#M62880</link>
      <description>&lt;P&gt;A great deal depends on what your doing,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have inbound rules for NAT to inside hosts?&lt;/P&gt;&lt;P&gt;Do any of the third parties you connect to have IP address restrictions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A "Cutover" period migration from one to the other would be ideal rather than a Straight complete swap over.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both can run at the same time, and you can use PBF to move traffic out the second link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 13:33:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/217348#M62880</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-06-11T13:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/217367#M62883</link>
      <description>&lt;P&gt;Make sure to check your default outgoing NAT rule as well. If it is set to source translate to the interface address then you will be fine, otherwise the configuration will need to be amended to your new public IP range.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 15:29:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/217367#M62883</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-11T15:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/217368#M62884</link>
      <description>&lt;P&gt;I am not in the office...we can afford&amp;nbsp;some downtime...i just need to do this quickly...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a VPN tunnle with another office so i need to change that as well...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if I use PFB, Can i remove it later without any downtime?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also, when I access the firewall public IP...i am redirected to Global Protect Page, not the firewall GUI page...any idea how to access it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I need to change the below:&lt;/P&gt;&lt;P&gt;- Interface IP&lt;/P&gt;&lt;P&gt;-Global Protect portal&lt;/P&gt;&lt;P&gt;- Global protect gateway&lt;/P&gt;&lt;P&gt;- IKE Gateway&lt;/P&gt;&lt;P&gt;- One NAT policy&lt;/P&gt;&lt;P&gt;- Default route..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you think of something else?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will the VPN work after changing the IP address and resetting it?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 15:29:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/217368#M62884</guid>
      <dc:creator>Si_Infrastructure</dc:creator>
      <dc:date>2018-06-11T15:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/219781#M63427</link>
      <description>&lt;P&gt;ISP was changed successfully...for all of the network engineers out there...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Change the interface IP&lt;/P&gt;&lt;P&gt;- Chane the default route&lt;/P&gt;&lt;P&gt;- Change GlobalProtect settings&lt;/P&gt;&lt;P&gt;- Issue a new cert. for GlobalProtect&lt;/P&gt;&lt;P&gt;- Change the polices&lt;/P&gt;&lt;P&gt;-No need to reset the VPN&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 19:23:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/219781#M63427</guid>
      <dc:creator>Si_Infrastructure</dc:creator>
      <dc:date>2018-06-28T19:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/1226049#M123919</link>
      <description>&lt;P&gt;Hi Reaper, is the new Zone required (ex. I have existing "Untrust-A", I will create new "Untrust-B") is it required to have this working if I plug the new internet line in a free interface (eg. eth1/2)? Should I add the new Zone in every rule with existing Untrust?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 07:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-isp/m-p/1226049#M123919</guid>
      <dc:creator>Dars_Em</dc:creator>
      <dc:date>2025-04-09T07:48:43Z</dc:date>
    </item>
  </channel>
</rss>

