<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246821#M70273</link>
    <description>&lt;P&gt;With 2VRs you still need routes between them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF is checked before VR.&lt;/P&gt;&lt;P&gt;So if there is route in PBF then this will take precedence.&lt;/P&gt;&lt;P&gt;If no matching PBF then Palo falls back to routes in VR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This allows you to have 1 VR and PBF that has logic "if traffic comes from Guest zone then send it towards ISP2 and monitor ISP2. If ISP2 is not available then fall back VR"&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jan 2019 18:43:15 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2019-01-21T18:43:15Z</dc:date>
    <item>
      <title>ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246710#M70242</link>
      <description>&lt;P&gt;I am using a PA 3020.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an ISP1 which is our main corp internet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an ISP2 which is also our active Guest network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to configure ISP1 virtual router with Path Monitoring so that if fails pinging a group of IP's it fails over to ISP2 virtual router.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well I have configured Path Monitoring and can trigger it accordingly by monitoring a dead IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However I cannot get to the internet after this kicks in.&amp;nbsp;&lt;/P&gt;&lt;P&gt;From monitor tab I check my test laptop and the From Zone is till the same, and To Zone has changed. But everything says "aged-out" in the "Session End Reason" column.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas if there is another issue I need to check?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jan 2019 05:54:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246710#M70242</guid>
      <dc:creator>JohnQuile</dc:creator>
      <dc:date>2019-01-19T05:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246811#M70266</link>
      <description>&lt;P&gt;Why do you have 2 virtual routers?&lt;/P&gt;&lt;P&gt;Easier to have 1 virtual router.&lt;/P&gt;&lt;P&gt;Your could use PBF to route Guest network out from ISP2 link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check SNAT IP on outgoing traffic.&lt;/P&gt;&lt;P&gt;Does outgoing traffic match correct NAT rule and it is sourcing from ISP2 public IP?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 17:09:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246811#M70266</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-01-21T17:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246815#M70268</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 2 Virtual Routers existed before I inherited the management of the PA (inherited by network admin leaving, which hopefully explains my newbiness).&lt;/P&gt;&lt;P&gt;I am not sure I can swap out everything with 1 single Virtual Router and a PBF right now.&lt;/P&gt;&lt;P&gt;I was hoping to just get Path Monitoring setup with current setup to get ISP redundancy soon, and then have some cushion later to play around with 1 VR and PBF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I tested the ISP failover with how it is setup now, enabling Path Monitorign to ping a phantom IP (32.32.32.32), it just disconencted my laptop and I couldn't ping or get to websites.&lt;/P&gt;&lt;P&gt;When I checked the traffic log, I could see my requests going to new destiation zone and interface of ISP2, and ISP2's NAT IP.&lt;/P&gt;&lt;P&gt;But on my laptop I just got errors in my browser when trying websites, and no reply when pinging 8.8.8.8 in cmd prompt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The "General" application log says "incomplete" though for that traffic.&lt;/P&gt;&lt;P&gt;PA support advised maybe it is another switch, that the PA is handing traffic back into our network but my laptop is not getting it? I am not sure what to check to troubleshoot this. we do have 2 HP switches in the MDF&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 17:24:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246815#M70268</guid>
      <dc:creator>JohnQuile</dc:creator>
      <dc:date>2019-01-21T17:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246817#M70269</link>
      <description>&lt;P&gt;If VR1 routes traffic to VR2 and VR2 to internet.&lt;/P&gt;&lt;P&gt;Does VR2 have route back towards VR1 for return traffic?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 17:31:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246817#M70269</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-01-21T17:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246818#M70270</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well I'm not sure. Would this be established via a Static Route within the VR?&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as VR2 route back to VR1, this could be setup so only when it is failed over? Because on a normal day to day basis, VR2 with ISP2 is used all day as a guest network and functions fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's just trying to leverage it as a failover for our ISP1 and corp zone when ISP1 goes down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 17:34:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246818#M70270</guid>
      <dc:creator>JohnQuile</dc:creator>
      <dc:date>2019-01-21T17:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246819#M70271</link>
      <description>&lt;P&gt;Let's assume that internal network is 10.0.0.0/24 and guest network is 192.168.1.0/24&lt;/P&gt;&lt;P&gt;In this case you need to have static route in VR2 to send traffic towards 10.0.0.0/24 towards VR1.&lt;/P&gt;&lt;P&gt;It will not affect traffic from VR2 to internet because this has default route 0.0.0.0/0 and it would not allow guest traffic to internal becvause Security Policy will take care of that part.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 18:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246819#M70271</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-01-21T18:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246820#M70272</link>
      <description>&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Ahhh ok that makes sense. I will try that. So that would still be require if I did Policy Based forwarding too?&lt;BR /&gt;But if i consolidated to one VR it would make it easier ?</description>
      <pubDate>Mon, 21 Jan 2019 18:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246820#M70272</guid>
      <dc:creator>JohnQuile</dc:creator>
      <dc:date>2019-01-21T18:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246821#M70273</link>
      <description>&lt;P&gt;With 2VRs you still need routes between them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF is checked before VR.&lt;/P&gt;&lt;P&gt;So if there is route in PBF then this will take precedence.&lt;/P&gt;&lt;P&gt;If no matching PBF then Palo falls back to routes in VR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This allows you to have 1 VR and PBF that has logic "if traffic comes from Guest zone then send it towards ISP2 and monitor ISP2. If ISP2 is not available then fall back VR"&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 18:43:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246821#M70273</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-01-21T18:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246828#M70275</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Well I will definitely first try the route setup next. I'm excited that it makes sense and am motivated to try this at the next earliest, possible maintenance window overnight versus weekend.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me give this a go, and report back. Hopefully you won't mind visiting back to see how it goes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 19:47:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246828#M70275</guid>
      <dc:creator>JohnQuile</dc:creator>
      <dc:date>2019-01-21T19:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246839#M70278</link>
      <description>&lt;P&gt;Definitely let know how it went.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 22:23:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/246839#M70278</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-01-21T22:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/247390#M70382</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Sorry I meant to include screenshot earlier, if this helps identify any issues you see?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So basically, I need to add a route there on the "Virtual Router - guest-vr" to the subnet of computers that go through the "trust-vr" Virtual Router"?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-01-24_10-26-35.png" style="width: 953px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18427i51D9FDEF13753FB5/image-dimensions/953x834/is-moderation-mode/true?v=v2" width="953" height="834" role="button" title="2019-01-24_10-26-35.png" alt="2019-01-24_10-26-35.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 16:29:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/247390#M70382</guid>
      <dc:creator>JohnQuile</dc:creator>
      <dc:date>2019-01-24T16:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISP failover with Path Monitoring help? Incomplete Aged-out traffic issue. PA 3020</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/247650#M70462</link>
      <description>&lt;P&gt;That worked -- just added routes from the secondary VR to subnets of where our workstations were to go through the next vr.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Failover worked flawlessley. Not time to consider Policy based forwarding next.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps the next average Joe!&lt;/P&gt;&lt;P&gt;Thanks for guidance,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jan 2019 01:50:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-failover-with-path-monitoring-help-incomplete-aged-out/m-p/247650#M70462</guid>
      <dc:creator>JohnQuile</dc:creator>
      <dc:date>2019-01-26T01:50:51Z</dc:date>
    </item>
  </channel>
</rss>

