- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-11-2018 08:20 AM
Hi,
I am looking to explore options that in a situation when the External Edge may be "up" but, the internal resources have failed. For example, a core switch has crashed but, the firewalls and internet routers are still online. Users will connect to the gateway via GP but, no be able to access resources. What is a way to migrate users dynamically or stop advertising a gateway for a period to avoid new connections?
01-11-2018 09:14 AM
Hi, i don't have an answer but have posted here for any further updates.
I could never find an easy way to prevent users from connecting to a particular gateway.
I have removed the gateway from GP portal settings but this seems to take days to fully propogate.
the only solution I have used in the past is to change the IP address on the offending gateway. this prevents GP users from getting the initial SSL handshake and thus prevents any further connections. it also forces a rediscover (if set to always on) and users will auto migrate to another gateway.
I am however only able to do this as we have dedicated PA's for our gateway services with no other incoming traffic.
hopefully ther is a friendlier option......
01-11-2018 11:35 AM
My SE told me PAN has no feature for this scenario and recommend a script to disable the gateway.
01-11-2018 11:37 AM - edited 01-11-2018 11:39 AM
I don't think there is anything built in that has this ability. However you could likely script something using the API that would trigger on certain conditions that would perform @Mick_Ball's suggestion.
*edit
You must have updated right before I posted this. Let me know if you want/need any help with the API commands @nicford
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!