<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN-OS SDWAN tunnel failover in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-sdwan-tunnel-failover/m-p/391946#M90817</link>
    <description>&lt;P&gt;It seems to me that some of the parameter has been created wrongly by auto vpn. A backup physical interface has been attached to sdwan.902 instead of 901. And there is no zone configuration for two tunnels on hub firewall. I have attached the screenshots here. Could anyone kindly suggest what could be done to resolve the issue? Thank you&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 46.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30417i43747AFE7FC146DC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 46.jpg" alt="Image 46.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 48.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30418i36F864B2A6636638/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 48.jpg" alt="Image 48.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Mar 2021 09:30:23 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2021-03-18T09:30:23Z</dc:date>
    <item>
      <title>PAN-OS SDWAN tunnel failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-sdwan-tunnel-failover/m-p/391936#M90816</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I have recently setup a SD-WAN between 2 PA firewalls. a default route was created automatically to sdwan.1. Though when one of the interface failed, it is not able to failover to the remaining tunnel which mapped to sdwan.2. May I know if I need to manually create a route for sdwan.2 though I could not find the interface under the static route setting (p.s I am using static route in my testing environment)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Elroy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 08:31:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-sdwan-tunnel-failover/m-p/391936#M90816</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2021-03-18T08:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS SDWAN tunnel failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-sdwan-tunnel-failover/m-p/391946#M90817</link>
      <description>&lt;P&gt;It seems to me that some of the parameter has been created wrongly by auto vpn. A backup physical interface has been attached to sdwan.902 instead of 901. And there is no zone configuration for two tunnels on hub firewall. I have attached the screenshots here. Could anyone kindly suggest what could be done to resolve the issue? Thank you&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 46.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30417i43747AFE7FC146DC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 46.jpg" alt="Image 46.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 48.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30418i36F864B2A6636638/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 48.jpg" alt="Image 48.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 09:30:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-sdwan-tunnel-failover/m-p/391946#M90817</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2021-03-18T09:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS SDWAN tunnel failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-sdwan-tunnel-failover/m-p/391962#M90822</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I would firstly force the template value.&amp;nbsp;Those tunnel interfaces should have zone-internal attached to them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that does not work, create a layer 3 zone and make a dummy change on panorama and commit to the firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 11:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-sdwan-tunnel-failover/m-p/391962#M90822</guid>
      <dc:creator>ALI.KAYS</dc:creator>
      <dc:date>2021-03-18T11:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS SDWAN tunnel failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-sdwan-tunnel-failover/m-p/392237#M90879</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I do use panorama to do the config and tried to force template value already. Can you share what config to be changed on panorama as I cannot override the setting on the firewall itself and somehow the interface seems to be attached to the wrong tunnel as the screenshot shown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Elroy&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 02:58:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-sdwan-tunnel-failover/m-p/392237#M90879</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2021-03-19T02:58:23Z</dc:date>
    </item>
  </channel>
</rss>

