Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

PA with Two ISPs NAT

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA with Two ISPs NAT

Not applicable

Dears,

We have four zone in the PA. The naming along with subnet are below mentioned.

1. ISP1- 100.100.100.2/29

2. ISP2- 200.200.200.2/29

3. DMZ1- 172.16.1.1/24

4. DMZ2-172.10.1.1/24

5. Inside- 10.10.10.0/24

Inside user are going to internet via ISP1 and ISP2 is used for accessing in the DMZ1 and DMZ2.

Since the default route is configured towards the ISP1. We are facing the issue to access the servers in DMZ1 and DMZ2 via ISP2.(Destination Nat is configured for these servers via ISP2).

As per the logs the session from ISP2 to DMZ1 and ISP2 to DMZ2 are showing incomplete.I tried to configure PBF but it is not working.


Kindly let me know how DMZ1 and DMZ2 servers can accessible via ISP2.

Best Regards,

1 accepted solution

Accepted Solutions

L7 Applicator

Hello Parvez,

Here's a good document with a network diagram which can help. Symmetric return eature forwards the packet to the MAC address from where the SYN or lost packet was received.  This ensures return traffic follows the same interface which the session created and is useful in an asymmetric routing or Dual ISP environments.

How to Configure Symmetric Return

Hope this helps.

Thanks

View solution in original post

4 REPLIES 4

L7 Applicator

Hello Parvez,

Here's a good document with a network diagram which can help. Symmetric return eature forwards the packet to the MAC address from where the SYN or lost packet was received.  This ensures return traffic follows the same interface which the session created and is useful in an asymmetric routing or Dual ISP environments.

How to Configure Symmetric Return

Hope this helps.

Thanks

L6 Presenter

also when wan interface's are ppoe you don't need to write next hop, just selecting enforce return works.

I just want to double check that it will work for another DMZ2 host ; that is also need to be accessed via ISP2.

i.e. is PA-FW support two PBF on the same interface (ISP2) with different zone hosts(DMZ1 and DMZ2)?

Hello Parvez,

Yes, it will work.

Thanks

  • 1 accepted solution
  • 2964 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!