- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
08-24-2014 09:16 PM
Folks.
Current company is looking to expand to another site (yay for me - I get to upgrade my 2020's to 3020's at the head office!), however I'm in a bit of a quandary on getting the new site working.
The new site is going to have two internet links for diversity/redundancy, but I'm *not* going to be running BGP or any serious internet protocol at the edge.
What I'd like to do is terminate the internet (ethernet services) on the Palo Alto and run some form of weighted dynamic routing protocol - tell them to use link A as a primary, but if it fails to cutover to link B for the default route.
Does Palo Alto support something like Cisco's policy based routing to manage this? I don't want to just rely on link up/link down states to determine which link to run out of - I'd like to have some kind of active monitoring on the main link which knows when/if the link goes down and changes the default route to the second link.
Anyone know if this is possible? Or will it need manual intervention to cut over to the second link?
Thanks.
08-24-2014 09:19 PM
Hi Darren,
Its possible, kindly refer following document.
Dual ISP Branch Office Configuration
Regards,
Hardik Shah
08-24-2014 09:19 PM
Hi Darren,
Its possible, kindly refer following document.
Dual ISP Branch Office Configuration
Regards,
Hardik Shah
08-24-2014 09:23 PM
Sweet! Thanks.
The logic behind it is backward from what I would expect (the backup link being the default route), but I can make that work.
I assume this works on PanOS 5.x and 6.x as well?
Thanks again!
08-24-2014 09:28 PM
Hi Darren,
It works in all PAN-OS. Let me know for further difficulties.
Regards,
Hardik Shah
08-24-2014 09:30 PM
That's great information Hardik, thank you.
I'll be sure to come back if I can't make it work.
08-24-2014 09:37 PM
Hi Darren,
Any time any thing, also refer following documents for GP & IPsec in DUAL ISP.
https://live.paloaltonetworks.com/docs/DOC-4500
https://live.paloaltonetworks.com/docs/DOC-6036
https://live.paloaltonetworks.com/docs/DOC-3376
https://live.paloaltonetworks.com/docs/DOC-3190
Regards,
Hardik Shah
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!