<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Meraki and Palo side by side with Palo using BGP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388906#M90566</link>
    <description>&lt;P&gt;That's the solution we're going to implement once I get the config changes to the PA, the Merakis and our Core finalized.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for your help Tom.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Mar 2021 20:18:25 GMT</pubDate>
    <dc:creator>qdimclark</dc:creator>
    <dc:date>2021-03-03T20:18:25Z</dc:date>
    <item>
      <title>Meraki and Palo side by side with Palo using BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388659#M90525</link>
      <description>&lt;P&gt;We currently have this setup in our datacenter. The Meraki HA pair is the VPN endpoint for our 120+ remote sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="setup.jpg" style="width: 849px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30130i1294079338DF37DE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="setup.jpg" alt="setup.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In a DR situation the datacenter has IP mobility, where our current static IPs will failover. This setup uses BGP through the Palo.&amp;nbsp;With BGP enabled on the Palo HA Pair and datacenter’s internet the Meraki HA pair is inaccessible, which means the remote sites have no connectivity to the data center. The BGP config is exporting the 1.1.1.0/27 subnet, which obviously includes the Meraki IPs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we configure a rule on the Palo to allow traffic destined for the Meraki HA Pair to go to the Merakis without any other cabling or configuration changes?&amp;nbsp;The rule would look like this. Additionally it would allow only specific ports and protocols as needed.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-03-02 132554.jpg" style="width: 724px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30131iDFD398189CD5AF9C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-03-02 132554.jpg" alt="Screenshot 2021-03-02 132554.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To makes any other changes would require re-designing our current topology. We're trying to avoid that scenario for now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 18:38:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388659#M90525</guid>
      <dc:creator>qdimclark</dc:creator>
      <dc:date>2021-03-02T18:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki and Palo side by side with Palo using BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388833#M90547</link>
      <description>&lt;P&gt;the merakis will need to talk BGP as well to pick up their own IP addresses, else they'll need to be conected directly to the palo alto as a DMZ device so the palo can collect all ip's on the outside and forward the ones needed on the inside, to the merakis&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in this configuration you'll need to set up Uturn NAT which is probably going to interfere with ipsec performance&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 12:50:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388833#M90547</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-03-03T12:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki and Palo side by side with Palo using BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388858#M90553</link>
      <description>&lt;P&gt;That's what I suspected. But with limited BGP knowledge I thought I'd ask.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 16:11:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388858#M90553</guid>
      <dc:creator>qdimclark</dc:creator>
      <dc:date>2021-03-03T16:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki and Palo side by side with Palo using BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388896#M90562</link>
      <description>&lt;P&gt;Also, just and FYI Merakis can only use BGP within their AutoVPN (SD-WAN) feature. They can not use it in the scenario shown above.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 20:05:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388896#M90562</guid>
      <dc:creator>qdimclark</dc:creator>
      <dc:date>2021-03-03T20:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki and Palo side by side with Palo using BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388899#M90563</link>
      <description>&lt;P&gt;Your best bet would be to attach the merakis as DMZ devices so only the pan needs to BGP, and then forward ipsec to the merakis&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 20:07:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388899#M90563</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-03-03T20:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki and Palo side by side with Palo using BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388906#M90566</link>
      <description>&lt;P&gt;That's the solution we're going to implement once I get the config changes to the PA, the Merakis and our Core finalized.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for your help Tom.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 20:18:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-and-palo-side-by-side-with-palo-using-bgp/m-p/388906#M90566</guid>
      <dc:creator>qdimclark</dc:creator>
      <dc:date>2021-03-03T20:18:25Z</dc:date>
    </item>
  </channel>
</rss>

