Dual Isp - Two webserver

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Dual Isp - Two webserver

L1 Bithead

Hi all,

 

i have a problem, maybe stupid for all of you, but i can't understand how to configure my pan-220.

I had only one isp and all it's ok (internet, webserver, 2 vlans, etc).

Now i have another ISP and, if is possibile, i need to publish a web server with this connection (without failover. only publish a webserver with another ip)

Anybody can help me??? 

Thank you and sorry for my bad english!

8 REPLIES 8

Cyber Elite
Cyber Elite

@mariocutroneoYes it is possible.

 

Terminate new ISP on one of the empty interface of firewall. Do the configuration like IP, ZONE etc. Then use public IP of new ISP to publish your webserver. Kindly configure source, destination zones in Security and NAT policies.

 

Hope it helps!

 

Mayur

M

Thanks.. But i don't understand if i need a second virtuale router for this interface.

Thank you 

@mariocutroneo

 

No, no need of second Virtual Router.

Just one question, are you going to use this link only for hosting internal server or for passing internet traffic too?

 

Mayur

M

it's not working.

this is my config:

  • eth1/3 -> ISP2 
  • eth1/8  -> ISP1
  • eth1/4 - office LAN
  • vlan.1 -> office lan

 

zones

  • inside vlan
  • outside-isp1
  • outside -isp2

 

virtual router:

  • only one with all interfaces/vlan assigned

 

security:

  • outside-isp2 to inside vlan allow  my service

nat:

  • outside-isp2 to outside-isp2 -> destination address the ip of ISP2 - >destionation translation  -> the address of my webserver

 

if i switch the config changing isp2 to isp1 is working.

What 's wrong?

 

yes if is possibile, i'd like to pass  internet traffic too. 

 

thank you very much!

 

@mariocutroneoWhat are you seeing in traffic logs? I think, NAT is not happening in your case. NAT statement seems to be wrong. Please put statement as given below.

 

NATt:

  • outside-isp2 to 'inside' -> destination address the ip of ISP2 - >destionation translation  -> the address of my webserver

Security Policy is Ok.

 

Also if you still not able to access. Please see traffic logs and see if traffic coming from correct interface and NAT is happening properly. If it is still not working, then try by adding one static route for the ISP2 public IP (which is used for hosting web-server) towards ISP2 interface and IP address.

 

If you want to pass internet traffic through ISP2 link, you can add PBF for specific source IP/subnets to route internet traffic from ISP2 link. So this PBF rule will override your default route present in VR.

 

NOTE - As ISP2  is new link, can you please make sure you are able to ping next hop from Palo Alto interface. You can try to ping it from cli by taking source interface as IP address of interface eth1/3 (ISP2) and destination would be NEXT HOP or gateway of this link.

 

Hope it helps you!

 

Mayur

 

 

M

No nothing...

in logs i see that the packet is allow and the increment of hits count for nat -> outsideIsp2 to outsideIspd2

 

i also added the  static route in my virtual router, but nothing change.

 

yes, i can ping  from cli... 

 

😞

@mariocutroneo,

 

Can you please paste traffic log snap here?

 

Mayur

M

adding a second VR will make this a lot easier though

else you also want to set up Policy Based Forwarding so you can take advantage of 'symmetric return' (as else your return packets may go out of the other ISP and cause all kinds of problems

 

the second VR will prevent that

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 4372 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!