multi lan multi wan best practice

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

multi lan multi wan best practice

L1 Bithead

situation is this :

 

currently i have :

multiple lans/vlans

1 p2p line (single subnet static route0

1 internet line

1 virtual router

 

now, i need to add another wan

 

my best practice should be

a : to do another virtual router and separate relevant networks to each vr?

b : to "bag" everything under 1 vr with ecmp enabled + pbf?

c : maybe something i didn't think about?

 

in general, what are the advantages/disadvantages of using a single vr in such a case, as opposed to multiple vr?

because using a multiple vr seems like a whole lot of work "teaching" the vr's to the entire routing table of the opposite vr, but maybe i'm wrong...

 

thank you

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@paloaltouser2020,

 

Having multiple VRs would be the great choice when you have separate requirements all together, e.g. you want to have separate routing paths and those shouldn't shared between VRs etc. So choosing option among all available depends on the requirements and how are you going to manage it.

 

Looking at your use case and requirement, with single VR and ECMP should be the good option here. Also it will be very easy for you to manage it. I personally using same configuration on my several branch firewalls.

With multiple VRs, if you want to route traffic between the VRs, you need to have routes on respective VRs pointing to next hop as the destination VR where you want to reach. So you need to manage these things with multiple VRs. Having said that I would also say there are no as such major drawbacks of having any of the configuration (single or multiple VRs) as each has its own requirements and use cases.

 

 

M

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

@paloaltouser2020,

 

Having multiple VRs would be the great choice when you have separate requirements all together, e.g. you want to have separate routing paths and those shouldn't shared between VRs etc. So choosing option among all available depends on the requirements and how are you going to manage it.

 

Looking at your use case and requirement, with single VR and ECMP should be the good option here. Also it will be very easy for you to manage it. I personally using same configuration on my several branch firewalls.

With multiple VRs, if you want to route traffic between the VRs, you need to have routes on respective VRs pointing to next hop as the destination VR where you want to reach. So you need to manage these things with multiple VRs. Having said that I would also say there are no as such major drawbacks of having any of the configuration (single or multiple VRs) as each has its own requirements and use cases.

 

 

M

thank you so much for the detailed reply 🙂

 

in response to that : "each has its own requirements and use cases"

 

what are use cases where i'd want to use multiple vr's?

Hi @paloaltouser2020 ,

 

Multiple VRs can configured,

 

  1. To have separate routing paths for different traffic. And you want to keep routes isolated between VRs
  2. You may have heard about Cisco VRFs which is licensed based and comparatively these licenses are expensive. Now imagine PaloAlto multiple VRs here.
  3. Lets say you have Customer, Corporate and guest zones on single firewall and you want to use different routing for each zone.

In such and similar other cases, multi VRs would be helpful.

M

cool. many thanks 

  • 1 accepted solution
  • 2840 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!