Do I need an edge router in front of my Palo Alto?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Do I need an edge router in front of my Palo Alto?

L1 Bithead

having a general discussion about architecture with a colleague and after thoughts from a wider audience.

By deploying my Palo Alto in an Active/Active pair I can connect my firewalls directly to the ISP/MSP and use BGP to control route traffic.

 

 

My colleagues suggestion was it still needs the CE router where you can apply a simple zone based firewall/ACL on the router to limit the scope of traffic hitting our firewall. But I don't see any benefit in this. You can use Active/Active to overcome the limitation of needing FHRP for failover.

I was just wondering on other peoples thoughts.

2 REPLIES 2

Cyber Elite

Depends if ISP advertises full Internet routing table or only default route (and maybe routes originating from their AS).

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite

Hello,

My thoughts on modern design is you dont. But I'm sure there are special cases where you might.

Regards,

  • 2468 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!