Using Palo Alto PAN-OS SD-WAN for Redundant Internet (Dual ISP)

 


The SD-WAN topology is a single branch using Direct Internet Access (DIA) only with no hub.

Step 0: Verify SD-WAN License



Step 2: Create a SD-WAN Interface Profile



Step 3: Configure SD-WAN Physical Ethernet Interfaces








Step 4: Configure a Virtual SD-WAN Interface



Step 5: Create Static Routes to the SD-WAN Interface


default routes to ISP physical interfaces are optional



 6.1 create or use predefined Path Quality Profile
       measure Jitter, Latency and Packet loss

 6.2 create optional SaaS Quality Profile
    






 6.3 create Traffic Distribution Profile




Step 7: Configure SD-WAN Policy Rules



Step 8: Configure SD-WAN Interface NAT Rules






Refer this link for some troubleshooting command.

https://pan.dev/panos/docs/tutorials/redundant-internet/



Notes:

1. SDWAN interface only monitor default GW, can't detect indirect link failure.
2. SaaS Quality Profile is required to monitor indirect link failure.








How To Achieve ISP Failover In SD-WAN Direct Internet Access


https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001Vh7CAE



Understanding SDWAN Path Monitor States


Comments