Site with 2 X PA500 in HA
2 Internet Links
ISP1 - 22.214.171.124 (internet dedicated)
ISP2 - 192.168.0.66 (DSL link)
Virtual Router 1 - RT-LAN
Virtual Router 2 - RT-WAN
0.0.0.0/0 points to next VR "RT-WAN"
0.0.0.0/0 points to 1/1, next hop 126.96.36.199, metric 10
0.0.0.0/0 points to 1/2, next hop 192.168.0.254, metric 10
Sec Rules OK, NAT rules OK
Problem description: For some reason, PA500 just uses ISP1.
If we go to routing table we see both paths OK... both 0.0.0.0 routes pointing to both ISPs, with "A S E" flags
If we try to trace from public ISP2 interface, PA500 sends the packets to ISP1
admin@FW-0001> traceroute source 192.168.0.66 host 188.8.131.52 >>>>>ISP2 interface
traceroute to 184.108.40.206 (220.127.116.11), 30 hops max, 40 byte packets
1 rindal-virtual-ethernet1-1-3.1664.totalplay.com.mx (18.104.22.168) 8.154 ms 7.897 ms 8.012 ms >>>>>ISP1 GW
2 10.180.59.84 (10.180.59.84) 3.950 ms 3.842 ms 3.899 ms
3 10.180.59.85 (10.180.59.85) 3.124 ms 3.147 ms 3.249 ms
We have another box in PANOS 8.0.6 confugured the samw way... and the behavior is 100% OK
>> ping from src ISP1 always goes out thru ISP1 link
>> ping from src ISP2 always goes out thru ISP2 link
Is there any ECMP BUG related to PANOS 7.1.16 ?
Is there any other best practices to follow ?
Thanks in advance!
PAN-88213 was supposted to address an issue that effected ECMP and session offloading where it sent traffic to an incorrect next hop.
It sounds more like you are running into PAN-77747 that was supposed to be addressed in 7.1.12. I would open a support ticket so that PA can look at things and verify that 7.1.16 maybe didn't introduce a bug.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!