cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Seems best way to do is 

 

create vwire for both uplink connections.

 

here we will have 2 pair of vwires- Vwire INT and Vwire EXT

Two Zones trust and untrust

PA will pass all the LAG traffic  to dis switch from both zone trust zones.

 

As PA is passing traffic from both source interfaces of trust Zone and allowing return traffic from 2 dis switches we need to enable the option where PA allows asymm traffic

 

set deviceconfig setting tcp asymmetric-path bypass
# set deviceconfig setting session tcp-reject-non-syn no

 

MP

Help the community: Like helpful comments and mark solutions.

View solution in original post

Who rated this post