Two ISP Connection with some of my inside network going out one of the two

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Two ISP Connection with some of my inside network going out one of the two

L0 Member

Greetings,

 

Looking for some assistance in a scenario below; keep in mind I do not have or wish to have SD-WAN 

1. ISP1 services the inside and outside connections

2. ISP2 acts as a vpn portal for extenal staff to connect to the inside and route to ISP1

 

The problem.

 

I would like to force some of my inside servers (mainly backing up to the cloud) to use the outgoing connection of ISP2

I have a /29 address space for ISP1

 

Im think more towards the line of PBR however not sure if this is achievable.

3 REPLIES 3

Cyber Elite
Cyber Elite

With static routes in virtual router you can only route based on destination IP.

If you need to make decision based on source IP/Zone then yes PBF is your best option.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Thank you very much for your response.  I was wondering if PBR would require me to create a seperate Virtual Router?  Seeing i'm only allowed to have one 0.0.0.0/0 route I was thinking if I create another Virtual Router I could point that 0-Route to the interface of my secondary ISP?

Cyber Elite
Cyber Elite

When Palo needs to check route where to send traffic iit first checks PBF and if there is no matching policy then it will fall back to virtual router.

PBF policies take precedence over virtual router.

PBF and virtual router are not anyhow paired together.

 

Just create PBF policy to route specific traffic over ISP2 and you are done.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 1093 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!