<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you deal with Service Route and MGT port redundancy? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/281835#M76007</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;You have it correct for the managment interface. As for the service route, there is not one. Depeding on where the failure is, a HA pair might work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it depends.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2019 19:51:08 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-08-08T19:51:08Z</dc:date>
    <item>
      <title>How do you deal with Service Route and MGT port redundancy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/281799#M76005</link>
      <description>&lt;P&gt;We had an outage that took out a switch, and the PA management port is connected to that switch. I was unable to access the UI or CLI, and VPN was unable to authenticate via LDAP. I found the issue was that all the Service Routes were set to default using the MGT port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After looking through the settings, I see that I can assign a Management Profile to multiple interfaces, which would allow me to access the UI/CLI if the management port goes down. But that does not include Service Routes, which can only be assigned to a single interface- either the MGT port, or a another interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to make service routes redundant? Maybe something like a PBF rule for service routes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 15:58:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/281799#M76005</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2019-08-08T15:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: How do you deal with Service Route and MGT port redundancy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/281835#M76007</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;You have it correct for the managment interface. As for the service route, there is not one. Depeding on where the failure is, a HA pair might work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it depends.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 19:51:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/281835#M76007</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-08-08T19:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do you deal with Service Route and MGT port redundancy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/281975#M76020</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/25857"&gt;@Maxstr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately that is correct, service routes can be configured only through one interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However a workaround would be to configure service route based on destination. Take for example LDAP:&lt;/P&gt;&lt;P&gt;- You must leave the service route for LDAP on default&lt;/P&gt;&lt;P&gt;- On tab destinations configure two or more LDAP servers. Each server can be assignd with different interface&lt;/P&gt;&lt;P&gt;The catch here is that firewall will use the IP from the interface as source address when trying to connect to LDAP, BUT it will always perform route lookup first to check how to get to the LDAP server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 07:30:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/281975#M76020</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2019-08-09T07:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: How do you deal with Service Route and MGT port redundancy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/282316#M76076</link>
      <description>&lt;P&gt;Make the interface you want to attach the service route to a redundant (aggregate ethernet) interface.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2019 17:52:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/282316#M76076</guid>
      <dc:creator>TSilverline</dc:creator>
      <dc:date>2019-08-12T17:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: How do you deal with Service Route and MGT port redundancy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/282711#M76129</link>
      <description>&lt;P&gt;To add to TSilverLine -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aggregate ethernet going to two different switches (stacked, MC-LAG, etc)... &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 13:29:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-deal-with-service-route-and-mgt-port-redundancy/m-p/282711#M76129</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-08-14T13:29:56Z</dc:date>
    </item>
  </channel>
</rss>

