Saturday, April 4, 2020

ISP failover across two sites

I’ve got a design issue that I think should be straight forward but I’m just failing to implement here. Network diagram is https://imgur.com/a/9j1UaTP.

I have two sites, site A and site B each with a connection to the internet connected to a Palo Alto firewall. The Palo Alto then connects to a Cisco 3650 and our own fibre connects the two. We then have a number of satellite sites connected through various media which results in a more circuitous route from site A to B.

At the moment everything runs through Site A. The Palo Alto advertises a default route through OSPF and the rest of our network is EIGRP. The connections to the ISPs are static routes. I just want to have the Site B internet connection as a backup if A fails but also be able to use both if there’s a complete failure of the routes from A to B such as a fibre cut.

What would be the best way of doing this? Should I move the default route back off the Palo and onto the Ciscos instead? Should I bring up a direct link between the Palo Altos and use SLA tracking? Any help is greatly appreciated.



No comments:

Post a Comment