<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PBR on 5.0 with redundant internet connections questions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbr-on-5-0-with-redundant-internet-connections-questions/m-p/10434#M7692</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New to Palo Alto.&amp;nbsp; I think PBR is working right.&amp;nbsp; But functionality is not what I wanted to happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Cisco DMVPN from all my remote sites to my corporate site.&amp;nbsp; This tunnel is created inside of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my desired affect is to have 2 ISPs.&amp;nbsp; When the primary fails it dynamically fails over to the secondary internet.&amp;nbsp; Then when the primary comes recovers from the outage dynamically fail back to the primary ISP.&amp;nbsp; So VPN and web browsing would not be impacted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I have PBR set up so the default route is to the secondary ISP.&amp;nbsp; I have a PBR pointing at the primary watching an IP on the internet.&amp;nbsp; The NAT is set up accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am seeing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the Primary ISP fails.&amp;nbsp; It dynamically switches to the secondary internet.&amp;nbsp; What the 5 minutes for the DPDs.&amp;nbsp; Then all services are up and functional on the secondary link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the Primary ISP recovers they new sessions ride the primary ISP path.&amp;nbsp; Because the VPN is up it does not build a new session on the primary path.&amp;nbsp; I have to manually delete the session that the VPN tunnel has on the secondary interface.&amp;nbsp; Then the tunnel is on the primary interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not what I want to happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any feedback.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Feb 2013 17:21:02 GMT</pubDate>
    <dc:creator>JColby</dc:creator>
    <dc:date>2013-02-06T17:21:02Z</dc:date>
    <item>
      <title>PBR on 5.0 with redundant internet connections questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbr-on-5-0-with-redundant-internet-connections-questions/m-p/10434#M7692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New to Palo Alto.&amp;nbsp; I think PBR is working right.&amp;nbsp; But functionality is not what I wanted to happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Cisco DMVPN from all my remote sites to my corporate site.&amp;nbsp; This tunnel is created inside of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my desired affect is to have 2 ISPs.&amp;nbsp; When the primary fails it dynamically fails over to the secondary internet.&amp;nbsp; Then when the primary comes recovers from the outage dynamically fail back to the primary ISP.&amp;nbsp; So VPN and web browsing would not be impacted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I have PBR set up so the default route is to the secondary ISP.&amp;nbsp; I have a PBR pointing at the primary watching an IP on the internet.&amp;nbsp; The NAT is set up accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am seeing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the Primary ISP fails.&amp;nbsp; It dynamically switches to the secondary internet.&amp;nbsp; What the 5 minutes for the DPDs.&amp;nbsp; Then all services are up and functional on the secondary link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the Primary ISP recovers they new sessions ride the primary ISP path.&amp;nbsp; Because the VPN is up it does not build a new session on the primary path.&amp;nbsp; I have to manually delete the session that the VPN tunnel has on the secondary interface.&amp;nbsp; Then the tunnel is on the primary interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not what I want to happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any feedback.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 17:21:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbr-on-5-0-with-redundant-internet-connections-questions/m-p/10434#M7692</guid>
      <dc:creator>JColby</dc:creator>
      <dc:date>2013-02-06T17:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: PBR on 5.0 with redundant internet connections questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbr-on-5-0-with-redundant-internet-connections-questions/m-p/10435#M7693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JColby:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look at this document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3376" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will take a little time to wrap your head around, but it works quite well.&amp;nbsp; I set something like this up in the lab not too long ago and it worked like a charm.&amp;nbsp; Essentially, you'll have 2 VPN tunnels leaving your dual-ISP site, one through each ISP.&amp;nbsp; This involves configuring a 2nd virtual router, and then policy-forwarding one of the VPN tunnels through the 2nd ISP.&amp;nbsp; At that point, you should be able to configure a pair of overlapping/redundant routes that point at the VPN tunnels as their next-hop.&amp;nbsp; Using routing metrics you can influence which tunnels are preferred. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2013 21:31:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbr-on-5-0-with-redundant-internet-connections-questions/m-p/10435#M7693</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-02-26T21:31:19Z</dc:date>
    </item>
  </channel>
</rss>

