cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

VRRP with Cisco router LAN interface

L0 Member

My default branch configuration, the WAN router is the default route for the client devices on the LAN.  Lets say 10.10.1.1/24

My firewall is the default route of the WAN router, lets say 10.10.1.254/24.

Cheap layer 2 switfh on the LAN, so no L3 routing option there.

In the above setting, clients send all packets to WAN router, Internet traffic is then sent to firewall for local browsing.  private packets send over WAN circuit.  If WAN circuit fails, all packets sent to local firewall.

My firewall has a backup IPSec tunnel in case the WAN circuit goes down.

All above is fine if only the WAN circuit goes down.

 

I want to further this backup/redundnacy by running VRRP between my Cisco WAN router and the PA firewall. so if the Cisco WAN router dies, the firewall becomes the 10.10.1.1/24 address and thus the default route for the client devices on the LAN, and thus uses the IPSec backup tunnel.

In the past with Juniper firewalls, this was no problem, Juniper supports a VRRP group and virtual IP for the LAN Trusted interface.

I dont see this available on Palo Alto????

 

Who Me Too'd this topic