<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dual ISP with VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-with-vpn/m-p/231723#M66530</link>
    <description>&lt;P&gt;there's a picture of the routes on the secondary-vr further down in the article that shows it does have a default route:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13842_Routes for VPNs.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16715iB0FEAA35C0C5FCF8/image-size/large?v=v2&amp;amp;px=999" role="button" title="13842_Routes for VPNs.PNG" alt="13842_Routes for VPNs.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Sep 2018 11:16:44 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-09-21T11:16:44Z</dc:date>
    <item>
      <title>Dual ISP with VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-with-vpn/m-p/231557#M66484</link>
      <description>&lt;P&gt;I'm working on configuring a branch office firewall with two ISPs and Site-to-Site VPN to our data center.&amp;nbsp; The data center side has only 1 ISP connection&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm reviewing this article again, as I've used it in the past.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's been a while since I've done this setup, but something doesn't seem right. I get the two VR idea, since the traffic sourcing from the firewall does not use PBR. My issue is with the default route.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's examine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface configuration:&lt;/P&gt;&lt;P&gt;Configure two interfaces:&lt;/P&gt;&lt;P&gt;Eth 1/3: 10.185.140.138/24 (connection to ISP1) in the untrust zone&lt;/P&gt;&lt;P&gt;Eth 1/4: 10.80.40.38/24&amp;nbsp; (connection to ISP2) in the untrust zone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Virtual routers:&lt;/P&gt;&lt;P&gt;There are two virtual routers:&lt;/P&gt;&lt;P&gt;VR1: Primary (ISP1) (Ethernet1/3)&lt;/P&gt;&lt;P&gt;VR2: Secondary (ISP2) (Ethernet1/4)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Primary VR1, they have a default route pointing to the gateway of ISP1&amp;nbsp; 0.0.0.0/0 10.185.140.1.&amp;nbsp; Then, on Secondary VR2, they do not add a default route.&amp;nbsp; I also saw a post in the comments that you need a static default route configured on both VR1 and VR2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe both are incorrect, unless I'm missing something. &amp;nbsp;If you add a static route pointing to Primary ISP1 on VR1, it will cause issues with failover, even if you also have a default route on VR2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm thinking they meant to create the default route to the next hope for ISP2.&amp;nbsp; If correct, wouldn't that be on VR2?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 01:04:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-with-vpn/m-p/231557#M66484</guid>
      <dc:creator>MikeC</dc:creator>
      <dc:date>2018-09-20T01:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP with VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-with-vpn/m-p/231598#M66501</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46057"&gt;@MikeC&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;We're running this setup on one of our sites.&lt;BR /&gt;Both VR has default routes pointing to each individual ISP GW.&lt;/P&gt;&lt;P&gt;VR1 has my internal LAN segments and ISP1 interface. VR2 has only ISP2 interface. VR1 has a backup default-route pointing to next VR (VR2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 10:11:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-with-vpn/m-p/231598#M66501</guid>
      <dc:creator>theonewhoknocks</dc:creator>
      <dc:date>2018-09-20T10:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP with VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-with-vpn/m-p/231627#M66510</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;This can be accomplished with 1 VR and a PBF rule or dynamic routing (with weighted routes). Since both tunnels are up but you will only be using one at a time (assumption).&amp;nbsp; A 1 VR solution works well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 14:41:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-with-vpn/m-p/231627#M66510</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-20T14:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP with VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-with-vpn/m-p/231723#M66530</link>
      <description>&lt;P&gt;there's a picture of the routes on the secondary-vr further down in the article that shows it does have a default route:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13842_Routes for VPNs.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16715iB0FEAA35C0C5FCF8/image-size/large?v=v2&amp;amp;px=999" role="button" title="13842_Routes for VPNs.PNG" alt="13842_Routes for VPNs.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 11:16:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-with-vpn/m-p/231723#M66530</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-09-21T11:16:44Z</dc:date>
    </item>
  </channel>
</rss>

