- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-27-2022 07:31 AM
Hello,
I have two ISPs with Dynamic Public IPs. Is there a way to setup ISP failover?
Thanks,
Bill
10-27-2022 06:30 PM - edited 10-27-2022 06:36 PM
Hi @Bill-Jerome ,
Great question. I don't think it can be done with 1 NGFW because both static route path monitoring and PBF require a next hop to be configured. As I understand your scenario, your default routes are learned dynamically. However, with 2 NGFWs, you could enable Path Monitoring with 1 ISP on each NGFW. If you wanted to load balance between the two, it can be done but would be complicated. Primary/Standby would be the easiest scenario.
It is very important that you use multiple Internet IP addresses and set your Failure Condition to all so that if one Internet server goes down you do not fail over.
Thanks,
Tom
Edit: How often do your IP addresses change? You could do it with 1 NGFW and update your next hops whenever the IP address changes.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO
10-27-2022 08:29 PM
Thanks for the feedback. I was thinking about the next hop option too but was hoping for a way to use a FQDN for the next hop but that seem like wishful thinking. 🙂
Thanks,
Bill
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!