I want to use PBF with IPSEC tunnel to handle failover.
I have 2 tunnels with the same proxy id, so I need to route a network between one tunnel, and if this tunnel is down I need to automatically route to the second tunnel.
But how to use monitoring in the PBF rule with a tunnel interface?
I think I have to configure a IP on the tunnel interface, but in which network ?
Can you help?
You can the tunnel interface with any IP address as long as the IPSEC Peer is configured with the appropiate proxy ID/route.
For example, you can set the tunnel interface to 10.10.10.250/24 - this would require the peer to have 10.10.10.250/24 or 10.10.10.250/32 configured as the remote(PaloAlto) proxy ID.
Also, when configuring a IP address to 'monitor' you will want to set a IP address in the peer's proxy ID so the traffic will get pushed through the tunnel.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!