<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ECMP + 3 Internet links + Outgoing traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/241011#M69052</link>
    <description>&lt;P&gt;Hello.... we have 2 in HA... we deal with just 1... the active one...&lt;/P&gt;</description>
    <pubDate>Fri, 23 Nov 2018 17:14:20 GMT</pubDate>
    <dc:creator>FabioGarcia</dc:creator>
    <dc:date>2018-11-23T17:14:20Z</dc:date>
    <item>
      <title>ECMP + 3 Internet links + Outgoing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/240284#M68867</link>
      <description>&lt;P&gt;Hello friends!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have now 3 ISPs, we started to use load balancing (all methoeds tested);&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ScreenShot293.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17575i01B187F14B4DF6A7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ScreenShot293.jpg" alt="ScreenShot293.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Problem&lt;/STRONG&gt;: Sometimes, packets from PA220, interface 1/4 (ISP 1),&amp;nbsp; goes out to internet thru interface 1/5 (ISP 2).&lt;/P&gt;&lt;P&gt;User's traffic with no problem.. But PA220 internet traffic (VPN establishment for example) is inconsistent.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ScreenShot294.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17576iB24751FBB2732080/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ScreenShot294.jpg" alt="ScreenShot294.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PA220 VPN initial IKE traffic example&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;VPN Gateway A&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;PA220 IP a.a.a.a (int 1/4)&amp;nbsp; &amp;gt;&amp;gt;&amp;gt; peer IP b.b.b.b&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;At monitor &amp;gt; traffic we see&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;IP a.a.a.a (int 1/4) going thru int 1/5&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;VPN doesnt establish&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Scenario as per below:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;"VR-LAN" for LAN (lan interface + tunnel intrefaces)&lt;/P&gt;&lt;P&gt;"VR-WAN" for Internet links (all default routes with same cost)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Is there a way to internet traffic from PA220 be out of that load balacing ?&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 10:47:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/240284#M68867</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2018-11-19T10:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: ECMP + 3 Internet links + Outgoing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/240717#M68947</link>
      <description>&lt;P&gt;Your diagram has 2 firewalls but you're referencing specific interfaces in different firewalls.&amp;nbsp; Can you explain a bit more how it's cabled up?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 13:20:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/240717#M68947</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-11-21T13:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: ECMP + 3 Internet links + Outgoing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/241011#M69052</link>
      <description>&lt;P&gt;Hello.... we have 2 in HA... we deal with just 1... the active one...&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2018 17:14:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/241011#M69052</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2018-11-23T17:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: ECMP + 3 Internet links + Outgoing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/242020#M69277</link>
      <description>&lt;P&gt;Just setup a static route to the public IP on the endpoint for the VPN, via 1 of the 3 interfaces.&lt;/P&gt;&lt;P&gt;This way the VPN wil always go out via this specific route instead of randomly (as dictated via ECMP)&lt;/P&gt;&lt;P&gt;For redundancy you could setup multiple tunnels and have routing figure out the best path, but that would only work when the other side has a PaloAlto as well (or a Juniper SRX/SSG).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:20:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/242020#M69277</guid>
      <dc:creator>bigfloor</dc:creator>
      <dc:date>2018-12-04T11:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: ECMP + 3 Internet links + Outgoing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/242754#M69423</link>
      <description>&lt;P&gt;hello thanks for the reply... but the VPN doesnt establish very well..... because of the worng behavior at public interface...&amp;nbsp;&lt;/P&gt;&lt;P&gt;INT 1/4 public IP is 200.200.200.2... gateway is&amp;nbsp;200.200.200.1&lt;BR /&gt;&lt;BR /&gt;But that traffic from 1/4 (200.200.200.2) is going thru 1/5.... (NATed to 1/5 IP) and then VPN doesnt establish (the other side expect 200.200.200.2.... )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that is the main problem...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 19:47:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/242754#M69423</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2018-12-10T19:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: ECMP + 3 Internet links + Outgoing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/242901#M69465</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you missed my point.&lt;/P&gt;&lt;P&gt;You have 3 equal cost paths, making the FW semi-randomly choosing the path to the VPN endpoint Public IP.&lt;/P&gt;&lt;P&gt;By entering a single new route, just for the Public IP of the VPN Endpoint, to go out over only 1 of the interfaces, then you would have a consistend outgoing public IP. And when the return traffic comes in, it would follow the same route in reverse&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Florian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 21:56:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ecmp-3-internet-links-outgoing-traffic/m-p/242901#M69465</guid>
      <dc:creator>bigfloor</dc:creator>
      <dc:date>2018-12-11T21:56:40Z</dc:date>
    </item>
  </channel>
</rss>

