<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External BGP Static Route Advertisement, with Path Monitoring an inside net in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/external-bgp-static-route-advertisement-with-path-monitoring-an/m-p/343089#M85916</link>
    <description>&lt;P&gt;I have an existing LAN with two data centers. The firewalls at each are not in a cluster, and have different internal/external connections and tunnels, so changing to active/active it not possible. They each have separate DMZ's right now.&lt;BR /&gt;We need to build a new redundant DMZ.&lt;BR /&gt;I've implemented static routes with next hop of none for my Public IP's on each Palo, one side prepends the AS 3x times all routes learned correctly on the eBGP devices.&lt;BR /&gt;If either site goes down entirely, everything works as expected, all traffic in/out goes via the operational ISP BGP connection.&lt;BR /&gt;Issue is I need to monitor some internal addresses, so if only the router or switch goes down the Palo will stop advertising those static routes.&lt;BR /&gt;I've played around with static path monitoring, but issue is I can't path monitor on a different segment than I'm advertising on.&lt;BR /&gt;1. The palo will not allow me to add the static route with external interface, and then monitor another IP via the internal interface (generic ping works, if I ping using Bypass routing table and use specified interface it doesn't).&lt;BR /&gt;2. Setup a NAT to the internal switch interface, and tried to ping that, same thing, also tried adding static route of the NAT and internal IP to that VR and no change.&lt;BR /&gt;I don't want to add any more hardware or reconfigure the existing Palo's as Active/Active between the sites if I can help it.&lt;BR /&gt;See attached diagram.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Aug 2020 18:42:06 GMT</pubDate>
    <dc:creator>TomElkins</dc:creator>
    <dc:date>2020-08-10T18:42:06Z</dc:date>
    <item>
      <title>External BGP Static Route Advertisement, with Path Monitoring an inside net</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-bgp-static-route-advertisement-with-path-monitoring-an/m-p/343089#M85916</link>
      <description>&lt;P&gt;I have an existing LAN with two data centers. The firewalls at each are not in a cluster, and have different internal/external connections and tunnels, so changing to active/active it not possible. They each have separate DMZ's right now.&lt;BR /&gt;We need to build a new redundant DMZ.&lt;BR /&gt;I've implemented static routes with next hop of none for my Public IP's on each Palo, one side prepends the AS 3x times all routes learned correctly on the eBGP devices.&lt;BR /&gt;If either site goes down entirely, everything works as expected, all traffic in/out goes via the operational ISP BGP connection.&lt;BR /&gt;Issue is I need to monitor some internal addresses, so if only the router or switch goes down the Palo will stop advertising those static routes.&lt;BR /&gt;I've played around with static path monitoring, but issue is I can't path monitor on a different segment than I'm advertising on.&lt;BR /&gt;1. The palo will not allow me to add the static route with external interface, and then monitor another IP via the internal interface (generic ping works, if I ping using Bypass routing table and use specified interface it doesn't).&lt;BR /&gt;2. Setup a NAT to the internal switch interface, and tried to ping that, same thing, also tried adding static route of the NAT and internal IP to that VR and no change.&lt;BR /&gt;I don't want to add any more hardware or reconfigure the existing Palo's as Active/Active between the sites if I can help it.&lt;BR /&gt;See attached diagram.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 18:42:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-bgp-static-route-advertisement-with-path-monitoring-an/m-p/343089#M85916</guid>
      <dc:creator>TomElkins</dc:creator>
      <dc:date>2020-08-10T18:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: External BGP Static Route Advertisement, with Path Monitoring an inside</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-bgp-static-route-advertisement-with-path-monitoring-an/m-p/343101#M85917</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomElkins_0-1597085229760.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27240iA6CF8005A5B78995/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="TomElkins_0-1597085229760.png" alt="TomElkins_0-1597085229760.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 18:47:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-bgp-static-route-advertisement-with-path-monitoring-an/m-p/343101#M85917</guid>
      <dc:creator>TomElkins</dc:creator>
      <dc:date>2020-08-10T18:47:17Z</dc:date>
    </item>
  </channel>
</rss>

