URGENT VPN failover help needed

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

URGENT VPN failover help needed

L2 Linker

Hello Everyone,

 

We have an existing policy-based site-to-site VPN between our Palo Alto and client's Meraki.

The current VPN is to their Primary WAN IP address(Primary ISP). Now they have a secondary ISP. Both the primary and secondary ISPs are configured on the client's Meraki. I have to configure VPN failover on Palo Alto. Please help me out. I have read multiple articles but I have got more confused. 

1 REPLY 1

L7 Applicator

Hi @msdphi 

 

Is Palo alto side initiator here? I am assuming it and below are the configuration steps ( high level ).

 

On Palo Alto side, you need to configure two separate IPSEC tunnels towards client side ( towards ISP1 and ISP2 ). For both the tunnels, you will have same proxy IDs. 

 

Let’s say you have configured tunnel.1 interface for the tunnel with ISP1 IP and tunnel.2 interface for tunnel with ISP2 IP.

 

Now you will add two static routes for tunnel destination hosts/network pointing to tunnel.1 and tunnel.2 interfaces. Here, keep higher metric on the route pointing towards tunnel.2 interface. e.g. 10 metric for the route pointing to tunnel.1 and metric 11 for the route pointing to tunnel.2 interface.

 

For failover, you need to use path monitoring on the static route pointing towards tunnel.1 i.e. your primary ISP.

For this, you need to assign IP address on the tunnel interface i.e. tunnel.1 and take one remote end IP which is responding to ping requests. So, you can configure that IP as a destination. Firewall will ping that IP during configured internals. If primary tunnel goes down, remote end IP will stop responding to the ping requests. As soon as path monitoring is detected as DOWN , the route pointing to tunnel.1 interface will be removed from the forwarding routing table. So, after that automatically, request will be send towards tunnel.2 interface which nothing but your backup tunnel.

 

Once primary tunnel is back online and remote IP starts pinging from primary tunnel interface, route towards tunnel.1 interface will be added back and traffic will be pointed to Primary tunnel with ISP1. For static route path monitoring, refer this .

 

Client team also need to handle all the required configuration on their end so they can accept traffic from Palo Also side.

 

SutareMayur_0-1729506688079.png

 

M

Check out my YouTube channel - https://www.youtube.com/@NetworkTalks
  • 705 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!