How to Configure Dual VPNs with Dual ISPs from a Active Active Cluster to a Remote Site

Reply
SSM
L0 Member

How to Configure Dual VPNs with Dual ISPs from a Active Active Cluster to a Remote Site

Hello All,

How to Configure Dual VPNs with Dual ISPs from a Active Active Cluster to a Remote Site? Any reference document?

We want to connect first ISP to device 0 on the active/active cluster and connect another ISP to device 1.

Is it possible to do a link load balance with pbf ?

L7 Applicator

Re: How to Configure Dual VPNs with Dual ISPs from a Active Active Cluster to a Remote Site

Hello SSM,

Below mentioned docs might help you.

Setup

How to Configure Symmetric Return

Policy Based Forwarding

As per PBF, you can load share traffic based on address/application.

Thanks

SSM
L0 Member

Re: How to Configure Dual VPNs with Dual ISPs from a Active Active Cluster to a Remote Site

Hi Hulk,

I have read these 3 docs but the docs only mention about a single device.

Highlighted
L5 Sessionator

Re: How to Configure Dual VPNs with Dual ISPs from a Active Active Cluster to a Remote Site

If you need to setup links to two separate firewalls then you will need to configure active active HA.

Here is a guide that explains the deployment scenarios

Configuring Active/Active HA PAN-OS 4.0


Please ensure that you are not trying to get double capacity by using Active Active because if you have a failure of a device a single device will not be able to hold the load of two firewalls.

Hope this helps.

Thanks

Numan

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!