<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS x PAN 2 tunnels PBF backhaul internet static routes? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/420026#M93843</link>
    <description>&lt;P&gt;Are you running TM on the IPSec Tunnels themselves as well on the PBF rules?&amp;nbsp; I was just doing it on the PBF rules but added them to the actual tunnel interfaces as well.&amp;nbsp; Hoping that will solve my problem of having to manually restart&amp;nbsp; both tunnels when one goes down and all traffic stops passing.&amp;nbsp; &amp;nbsp;I have no STATIC routes for any of the CIDRs on the other ends of both tunnels, can anyone tell me if this is right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPSec Tunnel:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_2-1626454860532.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35092i990BE864C32AE1DF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="drewdown_2-1626454860532.png" alt="drewdown_2-1626454860532.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_1-1626454838293.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35091i0C1A606D2BC3F753/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="drewdown_1-1626454838293.png" alt="drewdown_1-1626454838293.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jul 2021 17:01:54 GMT</pubDate>
    <dc:creator>drewdown</dc:creator>
    <dc:date>2021-07-16T17:01:54Z</dc:date>
    <item>
      <title>AWS x PAN 2 tunnels PBF backhaul internet static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395233#M91255</link>
      <description>&lt;P&gt;Anyone run into this before?&amp;nbsp; I have 2 x AWS tunnels (No BGP) and I want failover to occur and I want to backhaul internet traffic from AWS out through the PAN.&amp;nbsp; I have connectivity between AWS and on-prem with no static routes configured.&amp;nbsp; However, if I try to backhaul internet traffic from AWS across the s2s vpn tunnel (attached to TGW) it fails.&amp;nbsp; The only way I can get it to work is by adding a static route back to the AWS subnets in my VR.&amp;nbsp; But in doing so that won't allow the traffic to failover via PBF as far as I know.&amp;nbsp; Is that right and if not can someone explain how the correct way to make this work?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note I use PBF for dual ISP failover to the internet and am wondering if its in the same vein?&amp;nbsp; IE a static route to the backup path and PBF for the primary?&amp;nbsp; So what I am wondering do I need static routes configured in my VR? And if I do does PBF still trump the routing table?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 20:26:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395233#M91255</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-03-31T20:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: AWS x PAN 2 tunnels PBF backhaul internet static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395395#M91271</link>
      <description>&lt;P&gt;pbf takes precedence over the routing table of the firewall, but it will not override any routes you added to the VPC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you include a little drawing or some more info of what you're trying to accomplish ?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 12:11:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395395#M91271</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-04-01T12:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: AWS x PAN 2 tunnels PBF backhaul internet static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395410#M91275</link>
      <description>&lt;P&gt;Ok so even if I have static routes for the AWS subnets pointing to tunnel-A and PBF failing over to tunnel-B it should work? Basically I want all traffic to traverse tunnel-A and when that goes down switch over to tunnel-B.&amp;nbsp; &amp;nbsp;Not worried about the AWS side, just the right configuration on the PAN side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 13:38:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395410#M91275</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-04-01T13:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: AWS x PAN 2 tunnels PBF backhaul internet static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395412#M91276</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AWS-PAN-VPN-PBF.jpg" style="width: 731px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30695i1B313480D0AA6F98/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="AWS-PAN-VPN-PBF.jpg" alt="AWS-PAN-VPN-PBF.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 13:39:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395412#M91276</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-04-01T13:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: AWS x PAN 2 tunnels PBF backhaul internet static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395511#M91286</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;There are several ways to do this. I chose to use PBF and put the tunnels in over. Even PBF reads top to bottom so the first one that is a match, thats where it sends traffic. Also make sure to enable the monitor so the policy is disabled if the tunnel is down, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1617310416037.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30699i7EDE2AC1A4BACF78/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1617310416037.png" alt="OtakarKlier_0-1617310416037.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So for me it was two policies base forwarding policies. The other way would be one PBF and the second a static route down the second tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 20:54:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395511#M91286</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-04-01T20:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: AWS x PAN 2 tunnels PBF backhaul internet static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395547#M91289</link>
      <description>&lt;P&gt;correct, but make sure to set a monitor as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentioned so the PBF rule can be disabled if the monitor fails, else you will keep hitting the PBF even if it's "broken"&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 22:26:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/395547#M91289</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-04-01T22:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: AWS x PAN 2 tunnels PBF backhaul internet static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/420026#M93843</link>
      <description>&lt;P&gt;Are you running TM on the IPSec Tunnels themselves as well on the PBF rules?&amp;nbsp; I was just doing it on the PBF rules but added them to the actual tunnel interfaces as well.&amp;nbsp; Hoping that will solve my problem of having to manually restart&amp;nbsp; both tunnels when one goes down and all traffic stops passing.&amp;nbsp; &amp;nbsp;I have no STATIC routes for any of the CIDRs on the other ends of both tunnels, can anyone tell me if this is right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPSec Tunnel:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_2-1626454860532.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35092i990BE864C32AE1DF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="drewdown_2-1626454860532.png" alt="drewdown_2-1626454860532.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_1-1626454838293.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35091i0C1A606D2BC3F753/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="drewdown_1-1626454838293.png" alt="drewdown_1-1626454838293.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 17:01:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aws-x-pan-2-tunnels-pbf-backhaul-internet-static-routes/m-p/420026#M93843</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-07-16T17:01:54Z</dc:date>
    </item>
  </channel>
</rss>

