- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
04-03-2013 09:59 AM
Hi i have 5 internet connections (two dedicated links with different ISPs and 3 shared links with one ISP) , I need to configure the 5 untrust zones for internet and one for trust how i can configure the VR and how i can i use PBF per group of users. and create a backup link in case the first internet link goes down.
Regards,
04-03-2013 12:53 PM
PA currently doesnt support ECMP according to:
https://live.paloaltonetworks.com/message/18957#18957
which gives that if you wish to use all your 5 internet connections at once I would suggest you to use a router in front of your PA to do the routing and from that router use a single linknet which you then route the /24 or whatever you have assigned towards the PA unit.
This way the PA unit wont have to care about which connection was/is being used - for redundancy you can setup aggregated interfaces.
The result would be:
1) Internet (5 x connections)
|
2) Router (BGP preferly, but static would work aswell towards your ISPs)
[10.0.0.6/29]
|
[10.0.0.1/29]
3) PA
Your router would have a routing table similar to (regarding PA):
x.x.x.x/24 next 10.0.0.1
while your PA device would have:
0.0.0.0/0 next 10.0.0.6
Edit: Ahem *coughs*, highest usuable ip in the range 10.0.0.0/29 is 10.0.0.6 and not 10.0.0.7 which is the broadcast but I think you already got the point 😃
04-04-2013 07:38 AM
Many Thanks brother Mikand for your reply.
my concern we have 5 connections in these connections we have 2 dedicated internet links with 25m and we need to configure the 5 untrust zones and use PBF to add rules like IT group will forward to dedicated link number 1 which has 25mb and configure another rule for IT group to use dedicated link No. 2 in case first one goes down. and another AD groups we will decide to which link they can leave using PBF.
LAN ------------ PA -----------------untrust-1
-----------------untrust-2
-----------------untrust-3
----------------untrust-4
-----------------untrust-5
for this scenario we supose to use 6 interfaces one as trust (LAN) and 5 untrust (Internet zones).
for this scenario could you please inform me what is the best practice?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!