Cyberbulb
Cyberbulb
  • 3
  • 34 198
Palo Alto Networks IPsec VPN Troubleshooting
Troubleshooting ipsec vpn in Palo Alto Networks Firewall
Переглядів: 3 605

Відео

Palo Alto Networks Firewall - ISP Load balancing using ECMP
Переглядів 9 тис.2 роки тому
Through this video, you will learn the necessary steps to configure load balancing using ECMP "equal cost multi-path" and automatically detect link failures using path monitoring.
Configure Palo Alto Networks PANOS SDWAN
Переглядів 21 тис.2 роки тому
Through this video, you will learn how to configure paloalto panos sdwan. for a detailed guide refer to the following link: docs.paloaltonetworks.com/sd-wan/3-1/sd-wan-admin

КОМЕНТАРІ

  • @richardrugambwa883
    @richardrugambwa883 5 місяців тому

    Nice video and good explaination. Why do we have the sdwan.1 manual VIF since the Auto-VPN is creating sdwan.902? Can't it cause a conflict.

    • @Cyberbulb
      @Cyberbulb 5 місяців тому

      There's no one way to do it. You can use autovpn or manual SD-WAN. Also routing can be static or dynamic using bgp. But I prefer not to mix. If your wan topology is simple you can go for manual / static.

  • @Neur0bit
    @Neur0bit 7 місяців тому

    Fantastic explanation and demo. Bravo!

  • @bradl3811
    @bradl3811 7 місяців тому

    This also helped me with my configuration. Thank you very much.

  • @TranVanLamBDCVT-
    @TranVanLamBDCVT- 8 місяців тому

    Can you show me the Zones on the Panorama ?

    • @Cyberbulb
      @Cyberbulb 8 місяців тому

      If it is a green field it is better to create the following zones on panorama and use them zone-internet, zone-internal, zone-to-hub, and zone-to-branch

    • @Cyberbulb
      @Cyberbulb 8 місяців тому

      Creat the following zones on panorama: zone-internal zone-internet zone-to-hub zone-to-branch

  • @MB_72282
    @MB_72282 9 місяців тому

    Awesome! thanks

  • @eduardogabriel3944
    @eduardogabriel3944 10 місяців тому

    Is very helpful, thanks!!! Good lesson. 7:34

  • @No_Place_Here
    @No_Place_Here 10 місяців тому

    Why symmetric returns is important ?

    • @Cyberbulb
      @Cyberbulb 10 місяців тому

      if you have published services this option guarantees the return traffic is using the same internet link

  • @hamada99457
    @hamada99457 11 місяців тому

    keep it up

  • @miguelreyes3241
    @miguelreyes3241 Рік тому

    This helped me with my configuration. Thanks

  • @goureshnaik7257
    @goureshnaik7257 Рік тому

    Helpful video

  • @sudhakarsham36
    @sudhakarsham36 Рік тому

    thankyou , quick and very effective troubleshooting steps.

  • @vbb-t7h
    @vbb-t7h Рік тому

    Very helpful!

  • @SumanjusMontesQuispe
    @SumanjusMontesQuispe Рік тому

    No se agrego la politica de seguridad de LAN a las nuevas WAN.

  • @aswin05
    @aswin05 Рік тому

    Can we have Branch to Hub and also branch to branch ? also can we route an application through specific link ?

    • @Cyberbulb
      @Cyberbulb Рік тому

      Yes, you can. Branch to branch is through hub or may be direct if you choose mesh instead of hub and spokes in vpn cluster config

  • @gouthamm.n2644
    @gouthamm.n2644 Рік тому

    Could you also show the virtual router configurations?

    • @Cyberbulb
      @Cyberbulb Рік тому

      BGP configured using sdwan plugin auto configures virtual router. connected routes for branches are advertised using bgp. subnets added under hub "prefixes to redistribute" are reachable from branches through bgp routes as well. if you wish to use static routes, it will be another story to tell may be on my next video!

    • @gouthamm.n2644
      @gouthamm.n2644 Рік тому

      @@Cyberbulb got it I had issues with the loopback interface after fixing that the BGP was established I still have 1 more problem. Internet from zone-private to zone-internet does not work I do not see any hit counts on the nat policy which i have configured.

    • @Cyberbulb
      @Cyberbulb Рік тому

      if you have mapped the zones use the original zones in the policy like from trust to untrust as an example also check static default route that sdwan automatically create on the firewall with metric 5 @@gouthamm.n2644

  • @vijayyadav-pm5vv
    @vijayyadav-pm5vv Рік тому

    good

  • @mostafasafari8583
    @mostafasafari8583 Рік тому

    Thank you for your video. I have a bunch of branches and one hub. These branches are currently connected to the hub by IPSec tunnels, one for each branch. The tunnels are also part of the internal zone; therefore, we have L3-Trust (the internal network and tunnels) and L3-Untrust. If I want to use SD-WAN, should I define a third zone for tunnels? How should I map the zones?

    • @Cyberbulb
      @Cyberbulb Рік тому

      create zone-to-hub and zone-to-branch and map L3-Trust with internal and L3-Untrust with internet

  • @zacragoonath
    @zacragoonath Рік тому

    it was helpful, thanks.

  • @kauffmann1983
    @kauffmann1983 Рік тому

    Hello, Panorama is not necessary in order to implement SD-WAN, right?

    • @Cyberbulb
      @Cyberbulb Рік тому

      it should work without panorama as its role is the automation of VPN tunnels configurations and better monitoring

    • @chris71mach1
      @chris71mach1 Рік тому

      Most everything you do with multiple PAN firewalls will use Panorama as the central point. Whether you HAVE to or not (which I honestly think you do), it's going to be a lot less of a migraine if you have at least a PA-VM on your network.

  • @spm3365
    @spm3365 Рік тому

    Much appreciated, May I know the difference between the above configuration and the CloudGenix ION device configurations from Prisma-SDWAN portal.

    • @Cyberbulb
      @Cyberbulb Рік тому

      This is the sdwan integrated feature in paloalto ngfw. Cloudgenix is a dedicated sdwan solution.

    • @spm3365
      @spm3365 Рік тому

      @@Cyberbulb that is absolutely right. Lemme put my query in different way, what is the difference between the PANW's dedicated SDWAN (CloudGenix) methodology vs the PA-NGFW PANOS integrated SDWAN.

  • @Black_Swan68761
    @Black_Swan68761 2 роки тому

    Thanks for sharing the video.

  • @zmsaw
    @zmsaw 2 роки тому

    Please help with pcnse certification

  • @chris71mach1
    @chris71mach1 2 роки тому

    This was a great and concise explanation of Strata SD-WAN and its initial setup and requirements. Thanks for the vid, I think you've earned another subscriber!

  • @mahmoudabomosalm1893
    @mahmoudabomosalm1893 2 роки тому

    Good job 👍

  • @henryhajj1248
    @henryhajj1248 2 роки тому

    Amazing!