Using Palo Alto PAN-OS SD-WAN for Redundant Internet (Dual ISP)

 


The SD-WAN topology is a single branch using Direct Internet Access (DIA) only with no hub.

Step 0: Verify SD-WAN License



Step 2: Create a SD-WAN Interface Profile



Step 3: Configure SD-WAN Physical Ethernet Interfaces








Step 4: Configure a Virtual SD-WAN Interface



Step 5: Create Static Routes to the SD-WAN Interface


default routes to ISP physical interfaces are optional



 6.1 create or use predefined Path Quality Profile
 6.2 create optional SaaS Quality Profile


 6.3 create Traffic Distribution Profile

Step 7: Configure SD-WAN Policy Rules



Step 8: Configure SD-WAN Interface NAT Rules






Refer this link for some troubleshooting command.

https://pan.dev/panos/docs/tutorials/redundant-internet/



Notes:

1. SDWAN interface only monitor default GW, can't detect indirect link failure.
2. SaaS Quality Profile is required to monitor indirect link failure.






How To Achieve ISP Failover In SD-WAN Direct Internet Access


https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001Vh7CAE

Comments