Configuration of PA's - Internet Circuits

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Configuration of PA's - Internet Circuits

L1 Bithead

2017-12-09_19-34-15.png

Folks,

 

I'm new to the PA's, so I wanted to present this question for you.  I have two PA 5020's, in Active/Passive configuration shown above.  On each PA, eth1/4 and eth1/5 is in an aggregate group.  I have two Nexus 9504's as our core switches.  I two layer 2 VLAN's created.  One for each of our internet circuits.  I've created vPC for each of the interfaces for the port channels.  On the PA's, I've IP'd each aggregate sub-interface with the respective IP for each of the internet circuits.  Let's say that I have subinterface 299 and 300.  Sub-interface 299 is 1.1.1.2/30, and Sub-interface 300 is 2.2.2.2/30.  When I add a default 0 route, on the Nexus core swithces, that points to the public address of VLAN 299, the route doesn't add to the route table.  I'm assuming this is because the ARP table doesn't contain the public IP of the internet circuits.  Was wondering if anyone had any luck with this type of configuration, and if there was any insight you could give for this type of setup. 

 

 

1 accepted solution

Accepted Solutions

I haven't used Panorama in a while, so I'm not sure about the current interface.

 

Templates and groups are where you put settings that will be on multiple devices.

 

For settings like this that are specific to the individual device you change context to the specific PA in Panorama and then configure the setting there.

 

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

View solution in original post

3 REPLIES 3

L7 Applicator

In order for routes to be active the next hop has to be reachable.  So if you want to use vlan 299 and your default route the next hop in your example would be 1.1.1.2 on the PA interface.  This will be reachable on the Nexus and the route will be active.

 

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

I really appreciate your answer.

See that’s the thing, I can’t assign the sub interface the IP address on each individual Palo. So I went onto the panorama and assigned it to the device template and pushed it. However when I log into each PA, I still don’t see the IP address assigned. I thought this was part of where my problem was. Do I have to do anything special in panorama so it pushes the IPs to each device sub interface ? Thanks again

I haven't used Panorama in a while, so I'm not sure about the current interface.

 

Templates and groups are where you put settings that will be on multiple devices.

 

For settings like this that are specific to the individual device you change context to the specific PA in Panorama and then configure the setting there.

 

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 1 accepted solution
  • 2189 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!