Fail Over using Path Monitoring & NAT configuration

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Fail Over using Path Monitoring & NAT configuration

L3 Networker

I have a firewall wth 2 broadband circuits connected to it, one primary & one secondary.  My goal is to PAT all outbound traffic usinging the primary interface's public address but in a fail over situation I want to PAT all outbound traffic using the secondary interface public address. I configured path monitoring and believe that the static default route to the primary will get removed from the RIB if the circuit goes down but I'm not sure if failover will actually work since my global PAT is configured to use the pirmary interface public address Eth1/1 & I dont have another PAT rule configured.  I am half tempted to configure another PAT rule specifying the secondary interface but I can only imagine it will confilict with the primary.  Can someone with experience configuring failover in Palo Alto tell me if Path Monitoring is the best path to take in order to complete my goal & if so how NAT/PAT should be addressed.

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

You will need a PAT for each outbound interface. 

Regards,

I suppose the secondary PAT rule would need to be placed under the primary in the NAT policy? Is this correct?  Also how would this work if I intend on using the secondary internet circuit as VPN peer backup?  I have to dig into palo alto tunnel configurations a bit more but Im not sure that Path Monitoring would allow the secondary circuit to be on standby for use as a backup circuit only if the primary circuit goes down in the same way as a failover for VPN as well as internet?

Hello,

Yes it will be the same. two VR's are recommeded, however I accomplished the same thing with one VR in the past.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSeCAK

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGQCA0

 

Regards,

  • 3664 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!