Floating IP for Active-Active pair VPN

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L3 Networker

Floating IP for Active-Active pair VPN

Hi All,

 

I'm trying to configure a Floating IP for a VPN on an Active-Active pair of 5220's. I have the Floating IP configured with the Active-Primary Device Priority 1 and Active-Secondary with Device Priority 100. The Interface IPs for both devices are in different subnets to the Floating IP.

 

When I ping the floating IP from home, I see a log entry on the device for the ping but I never get a response from the ping.

 

Any idea's?

 

Regards

 

Adrian

Highlighted
L7 Applicator

how are you communicating with the upstream router(s)? Do you have bgp set up?

Tom Piens - PANgurus.com
New to PAN-OS or getting ready to take the PCNSE? check out amazon.com/dp/1789956374
Highlighted
L3 Networker

Yes. BGP is used between the firewall and the upstream routers. I see my ping in the firewall logs but I would have thought it would respond as it is tied to the interfaces rather than try to route through, especially out of a different interface.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!