<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing question - MPLS between two sites, with one of those connections being a failover ISP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10413#M7673</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you mean before writing that second pbf rule you can ping the interface but after that you can't&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 14 Apr 2013 14:45:32 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-04-14T14:45:32Z</dc:date>
    <item>
      <title>Routing question - MPLS between two sites, with one of those connections being a failover ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10406#M7666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a scenario in which I'm not sure how to proceed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two sites, both sites just got new circuits.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Site A, we have two new circuits (ISP #1 and ISP #2).&amp;nbsp; I've set up in my PA-500 Policy Based Forwarding to have ISP #1 as the primary internet connection, and if that drops, it will failover to ISP #2.&amp;nbsp; We've tested this and it works.&lt;/P&gt;&lt;P&gt;In Site B, we have one new circuit, also through ISP #2.&amp;nbsp; There is an MPLS private connection set up between Sites A and B through ISP #2, where PCs in Site B should be able to connect to server resources and files in Site A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have three interfaces configured on my PA-500:&amp;nbsp; Eth1/1 for the ISP#1, Eth1/2 for ISP#2, and Eth1/3 for LAN.&amp;nbsp; Because of the PBF failover rule, I have those three interfaces set up that way. I can ping from the Eth0/3 LAN interface on the PA-500 to a PC in Site B that is configured with a private LAN IP and the gateway pointing to the new circuit, so I know that the MPLS private connection is set up and the routing is correct.&amp;nbsp; However, I cannot be in the LAN zone with a PC on my side (gateway pointing to the PA-500 interface) and ping to that Site B PC.&amp;nbsp; I'm assuming that also means that the PC in Site B would only be able to ping up to the LAN interface on the PA-500, but not into the private LAN in Site A.&amp;nbsp; I've attached a diagram pic to give a visual.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I intially thought that I needed to add a static route for the private LAN subnet in Site B into the PA-500 in order for the connection to work, but I'm not sure how this works with the setup I have going (the ISP #2 being a secondary ISP line, but also where the private connection to the other site comes through).&amp;nbsp; In the "How to Configure Palo Alto Networks Firewalls when Connected to an MPLS Network" document, it talks about creating a separate interface for the MPLS connection, as well as separate zones/routes/policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do I do here to allow connections through from Site A to Site B with the interfaces set up the way I have them?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 21:34:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10406#M7666</guid>
      <dc:creator>uscit</dc:creator>
      <dc:date>2013-04-12T21:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Routing question - MPLS between two sites, with one of those connections being a failover ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10407#M7667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you attach your virtual router config ? or try that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can solve this by using 2 virtual routers for side A&lt;/P&gt;&lt;P&gt;eth interface of LAN for site1 use virtual router 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;virtual router 1 ----- default gw isp 1gw&lt;/P&gt;&lt;P&gt;virtual router 2 ----- default gw isp 2gw&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also you need adding some routes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for vr1 -&amp;nbsp;&amp;nbsp; for destination address "LAN of site2" subnet go to next VR and VR2&lt;/P&gt;&lt;P&gt;for vr2 -&amp;nbsp;&amp;nbsp; for destination address "LAN of site 1" go to next VR and VR1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Apr 2013 05:45:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10407#M7667</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-13T05:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Routing question - MPLS between two sites, with one of those connections being a failover ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10408#M7668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Current VR config (one VR):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interfaces included are all 3 (Ethernet1/1, Ethernet1/2, Ethernet1/3)&lt;/P&gt;&lt;P&gt;One static route of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Value&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AdminDistance&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Metric&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NoInstall&lt;/P&gt;&lt;P&gt;defaultroute&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eth1/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip-address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;gateway of ISP #2&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that helps.&amp;nbsp; I was reading through the above suggestion of 2 VR's, and I'm wondering:&amp;nbsp; do I still need to do some sort of NAT/Security/Zones for the private connection from Site B to Site A?&amp;nbsp; It's still a cloudy thought to me on configuring access to Site A's LAN resources for Site B on a private connection with ISP #2, that will also be used as a secondary ISP for Site A in general.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Apr 2013 14:00:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10408#M7668</guid>
      <dc:creator>uscit</dc:creator>
      <dc:date>2013-04-13T14:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: Routing question - MPLS between two sites, with one of those connections being a failover ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10409#M7669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok so you hava pbf rule for isp 1 is that right ?&lt;/P&gt;&lt;P&gt;can you write pbf rule(s) you have ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Apr 2013 06:13:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10409#M7669</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-14T06:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Routing question - MPLS between two sites, with one of those connections being a failover ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10410#M7670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, one PBF Rule:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISPFailover;&amp;nbsp; Source Zone is "LAN" on "Any" Address and User; Destination are all "Any"; action is Forward, egress through Eth1/1, next hop is &amp;lt;ISP#1 gateway&amp;gt;, enforce symmetric return is "false"; Monitor profile is "failover", target is 8.8.8.8, disable if unreachable is "false", schedule is "none".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Apr 2013 13:47:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10410#M7670</guid>
      <dc:creator>uscit</dc:creator>
      <dc:date>2013-04-14T13:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Routing question - MPLS between two sites, with one of those connections being a failover ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10411#M7671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you have to add another PBF to top of this rule which has destination address as SideB LAN to route from ISP2 gateway&lt;/P&gt;&lt;P&gt;Because when you wrote any as dest. address it forwards evrything to ISP1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Apr 2013 13:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10411#M7671</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-14T13:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Routing question - MPLS between two sites, with one of those connections being a failover ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10412#M7672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I created a second PBF as noted, destination of the Side B LAN, forward through Eth1/2 with next hop of &amp;lt;ISP#2 gateway&amp;gt;, and moved it above the failover PBF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, that doesn't help me as far as being in the PC in Site B and I can ping Eth1/2 (ISP#2 interface) but not Eth1/3 (LAN interface).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added a security policy to allow any traffic from the ISP2 Zone to the LAN zone, but that didn't help either.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Apr 2013 14:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10412#M7672</guid>
      <dc:creator>uscit</dc:creator>
      <dc:date>2013-04-14T14:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Routing question - MPLS between two sites, with one of those connections being a failover ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10413#M7673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you mean before writing that second pbf rule you can ping the interface but after that you can't&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Apr 2013 14:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10413#M7673</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-14T14:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Routing question - MPLS between two sites, with one of those connections being a failover ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10414#M7674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, i couldn't before writing the 2nd PBF rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As stated in the original post, I can ping from the Eth1/3 "LAN" interface all the way to a PC in Site B, but if I configure my PC within the LAN to point to the PA as gateway, I cannot ping to the PC in Site B from there...so nothing actually in the LAN can ping out past Eth1/3. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, from the other end, I can ping from the PC in Site B all the way to the Eth1/2 "ISP#2" Interface, but I cannot ping from the PC in Site B to the Eth1/3 "LAN" interface.&amp;nbsp; I did a tracert for these pings from the Site B PC...when tracing route from PC to Eth1/2 "ISP#2", the whole trace completes.&amp;nbsp; When tracing route from PC to Eth1/3 "LAN", the trace hits the "Customer Serial" interface of the ISP router, and then times out after that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited last sentence.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Apr 2013 14:58:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10414#M7674</guid>
      <dc:creator>uscit</dc:creator>
      <dc:date>2013-04-14T14:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Routing question - MPLS between two sites, with one of those connections being a failover ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10415#M7675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm back in office now, and was able to test a local PC on the LAN in Site A pinging to the PC in Site B after putting in the 2nd PBF rule, and it works.&amp;nbsp; Now, I have to figure out why I cannot ping through to the Site A LAN from the PC in Site B.&amp;nbsp; I have a feeling there is a missing static route on the Site A ISP's Router to the private LAN, since I can ping to the Eth1/2 "ISP#2" Interface but not to the Eth1/3 "LAN" interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 13:23:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-question-mpls-between-two-sites-with-one-of-those/m-p/10415#M7675</guid>
      <dc:creator>uscit</dc:creator>
      <dc:date>2013-04-15T13:23:46Z</dc:date>
    </item>
  </channel>
</rss>

