- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
03-24-2019 10:22 AM - edited 03-24-2019 10:26 AM
Seems best way to do is
create vwire for both uplink connections.
here we will have 2 pair of vwires- Vwire INT and Vwire EXT
Two Zones trust and untrust
PA will pass all the LAG traffic to dis switch from both zone trust zones.
As PA is passing traffic from both source interfaces of trust Zone and allowing return traffic from 2 dis switches we need to enable the option where PA allows asymm traffic
set deviceconfig setting tcp asymmetric-path bypass
# set deviceconfig setting session tcp-reject-non-syn no