We are transitioning from a 7K, 5K, 2K EVPC environment to an 9504, 93180, 2K one.Can FEXs be dual-homed to the 93180s?Which is the best design approach: Traditional VPC or Leaf and Spine L3 routed with ECMP?
Hello,I have a an IPSEC tunnel between an ASA5510 and PA820. When sourcing ping from 1.1.1.1 to 10.16.40.199, there are no replies. Encapsulated packets do increment on each side of the tunnel, according to each firewall. It appears as if the ASA doe...
Hello,Users have complained of slow Gmail acccess. After close inspection, it turns out that traffic is being redirected to an address of 192.168.42.46:8443. The address is in the WSA's configuration. It reads as follows:<prox_etc_error_page_logo_url...
Hello, I can source ping successfully from only a few of the SVIs on the switches. The successful SVIs are addressed 172.17.x.x. Others are 172.21.x.x. These fail. If it's any consolation, all of these segments are /22s. I verify this by attempting t...
I'm a little confused.Traffic wouldn't originate from 10.16.40.199 and be destined for DMZ-2 because 10.16.40.199 is in DMZ-2.I believe the rule in my last snapshot would permit traffic into DMZ-2. I understand. Thanks for the clarification.
Hmm, there is no rule with a source of DMZ-2 to Palo_VPN. Are you implying one is required? I'm not familiar with ASA vpn filters. How would I check for this. Thank you
10.16.40.199 lives on interface DMZ-2 off of the ASA. If I understand you correctly, you're saying I might need an access-list permitting traffic into dmz-2 from palo_vpn, right? Well, I do have an acl for this that permits anything...