Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

ISP Failover With Controlled Failback

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

ISP Failover With Controlled Failback

L0 Member

We have a pair of PA-3020 setup with HA and ISP Failover. PAN OS 9.1.3-h. I am not using PBF. I want to connect our VOIP phone switch to the firewall. Our VOIP phones connect to a cloud based PBX. I setup a new VR for VOIP with ports for ISP1, ISP2, and Inside. Failover / Failback works fine. Here is the problem. ISP1 goes Offline and the telephone call drops. Twenty seconds later the firewalls Failover and the dial tone comes back. You now call back the person you where disconnected from. While on the phone with them for the second time, ISP1 comes back online and the phone call drops again while the firewalls Failback to ISP1. This is a standard Metric based IPS Failover configuration. If ISP1 goes offline, I want my VOIP VR to stay active on ISP2 until such time that ISP2 goes offline and only then Failback to ISP1. We have separate VRs for Production, Guest, and now VOIP. NAT and Policies are setup and working properly. Any suggestions would be greatly appreciated. Thanks 

3 REPLIES 3

Cyber Elite
Cyber Elite

@AllanRaskin,

That's not really a thing with static route monitoring. You could set an artificially high preemptive hold timer which would prevent that failover until the link has been stable. This is slightly limited, but since it can be up to 1,440 minutes that really shouldn't be that much of an issue. 

Thank you for taking the time to respond. One thought, what if I add a second Path Monitoring Destination under Secondary-ISP-Route using Source: Outside-Secondary / Destination 8.8.8.8 and then change Failure Condition to "All"? Right now I have only one Condition, Source: Outside-Secondary / Destination: ISP2-Gateway. When both pipes are online does the Metric simply override Conditions? Thanks again.

Hello,

Disable preemptive failback.

OtakarKlier_0-1598649051111.png

This way the secodnary firewall will be running until you manually fail it back to the primary.

Regards,

  • 2667 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!