We are deploying two PA on AWS using GWLB and we are wondering what would happen if for any reason both aplliances go down , since all traffic (inbound , outbound and inter-vpc) is going through the FWs , do you know a quick bypass or fail-open solution to this? I configured a couple of linux2 machines with hairpining nat so they can send the traffic back to the gwlb in case of failure , using a secondary target group with these "bypass machines" but i dont know if you have any other idea or better design?
... View more