The PC-1 in Site - A, should be able to reach PC-20 in Site - B. To acomplish this, two VPNs will be configured over the two ISPs that are on each Site, in order to get redundancy and High Availability.

ISP routers will only have IP addresses configured on their interfaces, according to the topology.

Also, configure IP addresses on the end-hosts.


Before configuring the VPN tunnels and BGP routing, it is necessary to set the zones, interfaces and their IP addresses.
The first step is to configure the zones on the PaloAlto firewalls.
Considering the topology, the internal interface will be the “Trusted Zone”, and the outside interface will be the “Untrusted Zone”.
Network → Zones

By default, there is not any zones configured. Create 4 zones and assign an interface to each zone considering the topology.