The PC-1 in Site - A, should be able to reach PC-20 in Site - B. To acomplish this, two VPNs will be configured over the two ISPs that are on each Site, in order to get redundancy and High Availability.

topology-diagram.png

Background

ISP routers will only have IP addresses configured on their interfaces, according to the topology.

image.png

Also, configure IP addresses on the end-hosts.

image.png

image.png

Pre-config of PaloAlto

Before configuring the VPN tunnels and BGP routing, it is necessary to set the zones, interfaces and their IP addresses.

PaloAlto-1

Zones

The first step is to configure the zones on the PaloAlto firewalls.

Considering the topology, the internal interface will be the “Trusted Zone”, and the outside interface will be the “Untrusted Zone”.

Network → Zones

image.png

By default, there is not any zones configured. Create 4 zones and assign an interface to each zone considering the topology.