Dear Collegues, Let imagine the following situation: PA Firewall connected to two ISP, e1/1 - 1.1.1.1 and e1/4 - 2.2.2.2. Default virtual router with ECMP configured with weights e1/1-50 and e1/4-50. IPSEC tunnel configured to the remote site, IKE Gateway configured on interface e1/4. Tunnel is green, everything seems to be fine... but: I see around 50% packets lost. During troubleshooting I see that half of the ESP packets goes via e1/1 and other half via e1/4. Pacekts which goes via e1/1 has IP address of e1/4 (2.2.2.2) and are lost. I assume that I could use a PBF to resolve this issue, am I right? Best, Przemek
... View more