Static route path monitoring

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Static route path monitoring

L2 Linker

Hi All,

 

We have PA-820 models with Active-Passive configuration. 

 

I have configured the static route path monitoring based on this guideline - https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/networking/static-routes/static-route-remo...

 

 

Just would like to know, would there any impact in removing the static route from Primary RIB and replaces it with the secondary route if testing is carried out by "removing cable of the primary link port (facing to ISP)".

 

OR 

 

It's better to leave the cable connection of the primary link and just block the primary link source IP at the destination. In this way, the path monitoring wouldn't ping to a destination and it should replace with the secondary route.

 

 

I did the test with removing the primary link cable from the Active Palo Alto device and it didn't replace it with the secondary route. I guess, leave it cable in and block the source address at the destination its the best way. Any suggestions, please! 

 

 

Thank you.

 

CP

2 REPLIES 2

Hi @ChiragP ,

 

As you said it yourself the path monitoring is just a constant ping sent from the Palo Alto firewall to the monitored IP.

 

So in theory any reason for the pings packets to fail should disable the given static route. I would say both actions should end with same result.

 

The only different I can think of for disconnecting the interface is the link monitoring under the HA setting. Are you sure that when you disconnected the cable the firewall hasn't failover to secondary member where the cable was still connected?

 

Also I would suggest to check the FIB during your tests in order to be 100% sure which route is actually the active one:

> show routing fib | match <your-destination-network>

Hi Alexander,

 

Many thanks for the reply. 

 

I haven't done the test yet after your post so didn't reply. 

 

I will complete the test again and post the results. 

 

Thank you. 

 

Regards.

  • 4459 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!