AWS x PAN 2 tunnels PBF backhaul internet static routes?

Showing results for 
Show  only  | Search instead for 
Did you mean: 

AWS x PAN 2 tunnels PBF backhaul internet static routes?

L4 Transporter

Anyone run into this before?  I have 2 x AWS tunnels (No BGP) and I want failover to occur and I want to backhaul internet traffic from AWS out through the PAN.  I have connectivity between AWS and on-prem with no static routes configured.  However, if I try to backhaul internet traffic from AWS across the s2s vpn tunnel (attached to TGW) it fails.  The only way I can get it to work is by adding a static route back to the AWS subnets in my VR.  But in doing so that won't allow the traffic to failover via PBF as far as I know.  Is that right and if not can someone explain how the correct way to make this work?  


Note I use PBF for dual ISP failover to the internet and am wondering if its in the same vein?  IE a static route to the backup path and PBF for the primary?  So what I am wondering do I need static routes configured in my VR? And if I do does PBF still trump the routing table?  


Cyber Elite
Cyber Elite

pbf takes precedence over the routing table of the firewall, but it will not override any routes you added to the VPC


could you include a little drawing or some more info of what you're trying to accomplish ?

Tom Piens
PANgurus - (co)managed services and consultancy

Ok so even if I have static routes for the AWS subnets pointing to tunnel-A and PBF failing over to tunnel-B it should work? Basically I want all traffic to traverse tunnel-A and when that goes down switch over to tunnel-B.   Not worried about the AWS side, just the right configuration on the PAN side. 









There are several ways to do this. I chose to use PBF and put the tunnels in over. Even PBF reads top to bottom so the first one that is a match, thats where it sends traffic. Also make sure to enable the monitor so the policy is disabled if the tunnel is down, etc.



So for me it was two policies base forwarding policies. The other way would be one PBF and the second a static route down the second tunnel.


Hope that helps.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!