External up but, internal Outage, Migrating Users

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

External up but, internal Outage, Migrating Users

L2 Linker

Hi,

 

I am looking to explore options that in a situation when the External Edge may be "up" but, the internal resources have failed. For example, a core switch has crashed but, the firewalls and internet routers are still online. Users will connect to the gateway via GP but, no be able to access resources. What is a way to migrate users dynamically or stop advertising a gateway for a period to avoid new connections? 

3 REPLIES 3

L7 Applicator

Hi, i don't have an answer but have posted here for any further updates.

I could never find an easy way to prevent users from connecting to a particular gateway.

 

I have removed the gateway from GP portal settings but this seems to take days to fully propogate.

 

the only solution I have used in the past is to change the  IP address on the offending gateway. this prevents GP users from getting the initial SSL handshake and thus prevents any further connections. it also forces a rediscover (if set to always on) and users will auto migrate to another gateway.

 

I am however only able to do this as we have dedicated PA's for our gateway services with no other incoming traffic.

 

hopefully ther is a friendlier option......

 

 

My SE told me PAN has no feature for this scenario and recommend a script to disable the gateway. 

Cyber Elite
Cyber Elite

@nicford,

I don't think there is anything built in that has this ability. However you could likely script something using the API that would trigger on certain conditions that would perform @Mick_Ball's suggestion. 

 

*edit

You must have updated right before I posted this. Let me know if you want/need any help with the API commands @nicford

  • 2077 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!