ECMP Config for 2 Internet links Site (Dual ISP)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

ECMP Config for 2 Internet links Site (Dual ISP)

L3 Networker

 

Hello Everyone!

 

Site with 2 X PA500 in HA

2 Internet Links

PANOS 7.1.16

ISP1 - 187.190.74.22 (internet dedicated)

ISP2 - 192.168.0.66 (DSL link)

 

Config done

Virtual Router 1 - RT-LAN

Virtual Router 2 - RT-WAN

 

@RT-LAN

0.0.0.0/0 points to next VR "RT-WAN"

 

@RT-WAN

0.0.0.0/0 points to 1/1, next hop 187.190.74.1, metric 10

0.0.0.0/0 points to 1/2, next hop 192.168.0.254, metric 10

 

Sec Rules OK, NAT rules OK

 

Problem description: For some reason, PA500 just uses ISP1. 

If we go to routing table we see both paths OK... both 0.0.0.0 routes pointing to both ISPs, with "A S E" flags

 

If we try to trace from public ISP2 interface, PA500 sends the packets to ISP1

 

admin@FW-0001> traceroute source 192.168.0.66 host 8.8.8.8  >>>>>ISP2 interface
traceroute to 8.8.8.8 (8.8.8.8), 30 hops max, 40 byte packets
1 rindal-virtual-ethernet1-1-3.1664.totalplay.com.mx (187.190.74.3) 8.154 ms 7.897 ms 8.012 ms >>>>>ISP1 GW
2 10.180.59.84 (10.180.59.84) 3.950 ms 3.842 ms 3.899 ms
3 10.180.59.85 (10.180.59.85) 3.124 ms 3.147 ms 3.249 ms
^Cadmin@FW-0001>

 

We have another box in PANOS 8.0.6 confugured the samw way... and the behavior is 100% OK

>> ping from src ISP1 always goes out thru ISP1 link

>> ping from src ISP2 always goes out thru ISP2 link

 

Is there any ECMP BUG related to PANOS 7.1.16 ?

Is there any other best practices to follow ?

 

Thanks in advance!

 

 

3 REPLIES 3

L1 Bithead

What load balance method you are using?

Cyber Elite
Cyber Elite

@FabioGarcia,

PAN-88213 was supposted to address an issue that effected ECMP and session offloading where it sent traffic to an incorrect next hop. 

It sounds more like you are running into PAN-77747 that was supposed to be addressed in 7.1.12. I would open a support ticket so that PA can look at things and verify that 7.1.16 maybe didn't introduce a bug. 

Thanks for the reply..

 

we use IP Module

  • 3410 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!