Friday, January 18, 2019

Palo Alto 3020 - aged out sessions when traffic is allowed all outbound. ISP failover with path monitoring.

I'm attempting Path Monitoring on a Virtual router's Static Route that goes out via ISP1. I can force the path monitoring setting to trigger and go to the next VR if I put in a phantom IP to ping which will fail.
However when my test computer then tries to get any traffic out, it's giving an "aged-out" session end reason. I see the From zone is the same and the To Zone is now the "backup external" zone.
This ISP2 I'm trying to failover to is an active, working connection as it is the active "Guest network" as well and works just fine. So I'm curious if anyone's implemented this and maybe I'm missing an important setting to make it work.



No comments:

Post a Comment