<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: routing forwarding in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-forwarding/m-p/243686#M69641</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you want all traffic to go though the one site, then just put in a static route. Make sure you leave the specific routes for your ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i.e. PAN site A:&lt;/P&gt;&lt;P&gt;specific route for your isp, so the pan can get to the gateway so the VPN stays up.&lt;/P&gt;&lt;P&gt;then 0.0.0.0/0 with next hop the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN site B:&lt;/P&gt;&lt;P&gt;have a route for the site A subnets to next hop the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I prefer to use OSPF so that any changes are propgated automatically. However if you only have the two sites, statics will work just fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 18 Dec 2018 16:57:14 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-12-18T16:57:14Z</dc:date>
    <item>
      <title>routing forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-forwarding/m-p/243444#M69608</link>
      <description>&lt;DIV&gt;hey guys&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;If there is a site-to-site VPN between the FWs and I want to force some specific internet access traffic to go through&amp;nbsp;this VPN, is it possible?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Can I just add static routing on FW to force the specified traffic to the VPN tunnel?&lt;/SPAN&gt;&lt;DIV&gt;Do we need some config for the traffic which coming back?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 17 Dec 2018 04:50:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-forwarding/m-p/243444#M69608</guid>
      <dc:creator>qd_056</dc:creator>
      <dc:date>2018-12-17T04:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: routing forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-forwarding/m-p/243473#M69611</link>
      <description>&lt;P&gt;There are a few considerations in getting this to work.&amp;nbsp; You will need to consider both tunnel directions for the traffic routing and make sure the routes installed on both sides do what you wish and that the vpn itself will accept the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the routing, the question will be what direction is the traffic initiated.&amp;nbsp; Are you taking a public address on side A and forwarding requests to this address to a server on site B.&amp;nbsp; Or are you taking outbound traffic from site B and forwarding this to use the ISP outbound on site A.&amp;nbsp; For both cases you need to expand the policies inplace at site A and B to allow the traffic flow in the correct direction of initiation of session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For inbound traffic site A to site B you can set a normal fowarding rule to the address on the existing VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then add a source nat rule to an address on site A already covered in the VPN.&amp;nbsp; This won't require any VPN changes and the return traffic will work using the existing tunnel as is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the second case you would need to make sure the outbound web addresses on site B point to the tunnel interface of&amp;nbsp; a route based VPN.&lt;/P&gt;&lt;P&gt;You should use the open proxy-id on this vpn if at all possible.&amp;nbsp; If not the proxy-id pairs need to expand to include these public addresses as part of the tunnel.&lt;/P&gt;&lt;P&gt;On site A you will need to be sure the outbound source nat rule will cover the address range coming from site B going out that ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 12:06:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-forwarding/m-p/243473#M69611</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-12-17T12:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: routing forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-forwarding/m-p/243593#M69628</link>
      <description>&lt;P&gt;hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The real case is, when site A users want to access some dedicated websites. we want this traffic goes to siteB via the VPN between A and B and goes out from site B ISP, as we got poor performance while accessing such websites directly from site A.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 02:35:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-forwarding/m-p/243593#M69628</guid>
      <dc:creator>qd_056</dc:creator>
      <dc:date>2018-12-18T02:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: routing forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-forwarding/m-p/243686#M69641</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you want all traffic to go though the one site, then just put in a static route. Make sure you leave the specific routes for your ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i.e. PAN site A:&lt;/P&gt;&lt;P&gt;specific route for your isp, so the pan can get to the gateway so the VPN stays up.&lt;/P&gt;&lt;P&gt;then 0.0.0.0/0 with next hop the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN site B:&lt;/P&gt;&lt;P&gt;have a route for the site A subnets to next hop the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I prefer to use OSPF so that any changes are propgated automatically. However if you only have the two sites, statics will work just fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 16:57:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-forwarding/m-p/243686#M69641</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-12-18T16:57:14Z</dc:date>
    </item>
  </channel>
</rss>

