- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
08-25-2020 01:00 PM
We have a pair of PA-3020 setup with HA and ISP Failover. PAN OS 9.1.3-h. I am not using PBF. I want to connect our VOIP phone switch to the firewall. Our VOIP phones connect to a cloud based PBX. I setup a new VR for VOIP with ports for ISP1, ISP2, and Inside. Failover / Failback works fine. Here is the problem. ISP1 goes Offline and the telephone call drops. Twenty seconds later the firewalls Failover and the dial tone comes back. You now call back the person you where disconnected from. While on the phone with them for the second time, ISP1 comes back online and the phone call drops again while the firewalls Failback to ISP1. This is a standard Metric based IPS Failover configuration. If ISP1 goes offline, I want my VOIP VR to stay active on ISP2 until such time that ISP2 goes offline and only then Failback to ISP1. We have separate VRs for Production, Guest, and now VOIP. NAT and Policies are setup and working properly. Any suggestions would be greatly appreciated. Thanks
08-25-2020 04:16 PM
That's not really a thing with static route monitoring. You could set an artificially high preemptive hold timer which would prevent that failover until the link has been stable. This is slightly limited, but since it can be up to 1,440 minutes that really shouldn't be that much of an issue.
08-26-2020 11:22 AM
Thank you for taking the time to respond. One thought, what if I add a second Path Monitoring Destination under Secondary-ISP-Route using Source: Outside-Secondary / Destination 8.8.8.8 and then change Failure Condition to "All"? Right now I have only one Condition, Source: Outside-Secondary / Destination: ISP2-Gateway. When both pipes are online does the Metric simply override Conditions? Thanks again.
08-28-2020 02:13 PM
Hello,
Disable preemptive failback.
This way the secodnary firewall will be running until you manually fail it back to the primary.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!