<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dual Isp - Two webserver in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317719#M81659</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92413"&gt;@mariocutroneo&lt;/a&gt;Yes it is possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Terminate new ISP on one of the empty interface of firewall. Do the configuration like IP, ZONE etc. Then use public IP of new ISP to publish your webserver. Kindly configure source, destination zones in Security and NAT policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
    <pubDate>Fri, 20 Mar 2020 16:57:46 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2020-03-20T16:57:46Z</dc:date>
    <item>
      <title>Dual Isp - Two webserver</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317690#M81653</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a problem, maybe stupid for all of you, but i can't understand how to configure my pan-220.&lt;/P&gt;&lt;P&gt;I had only one isp and all it's ok (internet, webserver, 2 vlans, etc).&lt;/P&gt;&lt;P&gt;Now i have another ISP and, if is possibile, i need to publish a web server with this connection (without failover. only publish a webserver with another ip)&lt;/P&gt;&lt;P&gt;Anybody can help me???&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you and sorry for my bad english!&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 15:06:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317690#M81653</guid>
      <dc:creator>mariocutroneo</dc:creator>
      <dc:date>2020-03-20T15:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Isp - Two webserver</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317719#M81659</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92413"&gt;@mariocutroneo&lt;/a&gt;Yes it is possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Terminate new ISP on one of the empty interface of firewall. Do the configuration like IP, ZONE etc. Then use public IP of new ISP to publish your webserver. Kindly configure source, destination zones in Security and NAT policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 16:57:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317719#M81659</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-03-20T16:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Isp - Two webserver</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317742#M81661</link>
      <description>&lt;P&gt;Thanks.. But i don't understand if i need a second virtuale router for this interface.&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 19:35:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317742#M81661</guid>
      <dc:creator>mariocutroneo</dc:creator>
      <dc:date>2020-03-20T19:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Isp - Two webserver</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317765#M81664</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92413"&gt;@mariocutroneo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, no need of second Virtual Router.&lt;/P&gt;&lt;P&gt;Just one question, are you going to use this link only for hosting internal server or for passing internet traffic too?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 20:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317765#M81664</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-03-20T20:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Isp - Two webserver</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317820#M81669</link>
      <description>&lt;P&gt;it's not working.&lt;/P&gt;&lt;P&gt;this is my config:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;eth1/3 -&amp;gt; ISP2&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;eth1/8&amp;nbsp; -&amp;gt; ISP1&lt;/LI&gt;&lt;LI&gt;eth1/4 - office LAN&lt;/LI&gt;&lt;LI&gt;vlan.1 -&amp;gt; office lan&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;zones&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;inside vlan&lt;/LI&gt;&lt;LI&gt;outside-isp1&lt;/LI&gt;&lt;LI&gt;outside -isp2&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;virtual router:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;only one with all interfaces/vlan assigned&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;security:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;outside-isp2 to inside vlan allow&amp;nbsp; my service&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;nat:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;outside-isp2 to outside-isp2 -&amp;gt; destination address the ip of ISP2 - &amp;gt;destionation translation&amp;nbsp; -&amp;gt; the address of my webserver&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if i switch the config changing isp2 to isp1 is working.&lt;/P&gt;&lt;P&gt;What 's wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes if is possibile, i'd like to pass&amp;nbsp; internet traffic too.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you very much!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2020 10:26:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317820#M81669</guid>
      <dc:creator>mariocutroneo</dc:creator>
      <dc:date>2020-03-21T10:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Isp - Two webserver</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317825#M81671</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92413"&gt;@mariocutroneo&lt;/a&gt;What are you seeing in traffic logs? I think, NAT is not happening in your case. NAT statement seems to be wrong. Please put statement as given below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NATt:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;outside-isp2 to 'inside' -&amp;gt; destination address the ip of ISP2 - &amp;gt;destionation translation&amp;nbsp; -&amp;gt; the address of my webserver&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Security Policy is Ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if you still not able to access. Please see traffic logs and see if traffic coming from correct interface and NAT is happening properly. If it is still not working, then try by adding one static route for the ISP2 public IP (which is used for hosting web-server) towards ISP2 interface and IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to pass internet traffic through ISP2 link, you can add PBF for specific source IP/subnets to route internet traffic from ISP2 link. So this PBF rule will override your default route present in VR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTE - As ISP2&amp;nbsp; is new link, can you please make sure you are able to ping next hop from Palo Alto interface. You can try to ping it from cli by taking source interface as IP address of interface eth1/3 (ISP2) and destination would be NEXT HOP or gateway of this link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2020 13:05:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317825#M81671</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-03-21T13:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Isp - Two webserver</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317845#M81677</link>
      <description>&lt;P&gt;No nothing...&lt;/P&gt;&lt;P&gt;in logs i see that the packet is allow and the increment of hits count for nat -&amp;gt; outsideIsp2 to outsideIspd2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i also added the&amp;nbsp; static route in my virtual router, but nothing change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, i can ping&amp;nbsp; from cli...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2020 19:00:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317845#M81677</guid>
      <dc:creator>mariocutroneo</dc:creator>
      <dc:date>2020-03-21T19:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Isp - Two webserver</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317947#M81688</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92413"&gt;@mariocutroneo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please paste traffic log snap here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 08:18:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317947#M81688</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-03-23T08:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Isp - Two webserver</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317972#M81698</link>
      <description>&lt;P&gt;adding a second VR will make this a lot easier though&lt;/P&gt;&lt;P&gt;else you also want to set up Policy Based Forwarding so you can take advantage of 'symmetric return' (as else your return packets may go out of the other ISP and cause all kinds of problems&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the second VR will prevent that&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 12:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-two-webserver/m-p/317972#M81698</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-03-23T12:38:10Z</dc:date>
    </item>
  </channel>
</rss>

