{"id":543,"date":"2020-03-29T01:10:48","date_gmt":"2020-03-28T17:10:48","guid":{"rendered":"https:\/\/www.insecurewire.com\/?p=543"},"modified":"2020-03-29T01:10:48","modified_gmt":"2020-03-28T17:10:48","slug":"configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn","status":"publish","type":"post","link":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/","title":{"rendered":"Configuring ECMP on Palo Alto Firewalls with FTTN NBN"},"content":{"rendered":"<p>We have multiple campuses that are in Fibre to the Node NBN service areas. The cost to upgrade these campuses to full fibre starts at around $15k per campus. In lieu of this cost we have rolled out multiple VDSL FTTN connections to each campus that requires more bandwidth.<\/p>\n<p>To effectively load balance these VDSL circuits we use the Equal Cost Multi Pathing (ECMP) feature on the Palo Alto edge firewall. Each VDSL circuit has a static IPv4 address in different Internet routable subnets. We asked the ISP to make sure of this as the address is dynamically assigned (it is a reservation for each VDSL circuit). <\/p>\n<p>Each ISP supplied modem should be in bridge mode so that the address is assigned to the PA designated WAN interface and Internet routable. There are several components to this setup as follows:<br \/>\n<a href=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/diagram.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.insecurewi.re\/wp-content\/themes\/breek\/assets\/images\/transparent.gif\" data-lazy=\"true\" data-src=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/diagram.png\" alt=\"ECMP Network Diagram\" width=\"948\" height=\"447\" class=\"aligncenter size-full wp-image-573\" data-srcset=\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png 948w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram-300x141.png 300w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram-768x362.png 768w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram-100x47.png 100w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram-700x330.png 700w\" data-sizes=\"auto, (max-width: 948px) 100vw, 948px\" \/><\/a><\/p>\n<p>1. Configure each WAN interface on your PA (either dhcp or static) from your bridged modems. In this example we are load balancing across two circuits. Make sure each WAN circuit is in it&#8217;s own zone, for this example I am using WAN and WAN2.<br \/>\n<a href=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/interfaces.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.insecurewi.re\/wp-content\/themes\/breek\/assets\/images\/transparent.gif\" data-lazy=\"true\" data-src=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/interfaces-1024x87.png\" alt=\"Interfaces\" width=\"720\" height=\"61\" class=\"aligncenter size-large wp-image-546\" data-srcset=\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/interfaces-1024x87.png 1024w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/interfaces-300x25.png 300w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/interfaces-768x65.png 768w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/interfaces-100x8.png 100w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/interfaces-700x59.png 700w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/interfaces.png 1076w\" data-sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/a><br \/>\n2. Configure PA PAT rules for each source zone to WAN and WAN2. Port address translation will be in this example to dynamic-ip-and-port ethernet1\/1 and ethernet1\/8.<br \/>\n<a href=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/pat.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.insecurewi.re\/wp-content\/themes\/breek\/assets\/images\/transparent.gif\" data-lazy=\"true\" data-src=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/pat-1024x83.png\" alt=\"PAT\" width=\"720\" height=\"58\" class=\"aligncenter size-large wp-image-548\" data-srcset=\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/pat-1024x83.png 1024w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/pat-300x24.png 300w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/pat-768x63.png 768w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/pat-100x8.png 100w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/pat-700x57.png 700w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/pat.png 1069w\" data-sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/a><br \/>\n3. Enable ECMP on the virtual-router for your configuration. Enable symmetric return so that reply traffic goes out the wan interface it was received on. Set the load balancing algorithm, for this example we use &#8220;Balanced Round Robin&#8221;. Sessions not packets are equally balanced across the WAN circuits. In this example the Max Path is set to &#8216;2&#8217;. This is the number of default gateways that are the same. In this example it is 2 WAN circuits connected to the PA with 0.0.0.0\/0 routes.<br \/>\n<a href=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/ecmp.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.insecurewi.re\/wp-content\/themes\/breek\/assets\/images\/transparent.gif\" data-lazy=\"true\" data-src=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/ecmp.png\" alt=\"ECMP\" width=\"574\" height=\"270\" class=\"aligncenter size-full wp-image-547\" data-srcset=\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/ecmp.png 574w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/ecmp-300x141.png 300w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/ecmp-100x47.png 100w\" data-sizes=\"auto, (max-width: 574px) 100vw, 574px\" \/><\/a><br \/>\n4. Configure your firewall policy to enable traffic to leave the WAN and WAN2 interfaces destined for the Internet:<br \/>\n<a href=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/Internet.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.insecurewi.re\/wp-content\/themes\/breek\/assets\/images\/transparent.gif\" data-lazy=\"true\" data-src=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/Internet-1024x33.png\" alt=\"Security Policy\" width=\"720\" height=\"23\" class=\"aligncenter size-large wp-image-549\" data-srcset=\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/Internet-1024x33.png 1024w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/Internet-300x10.png 300w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/Internet-768x25.png 768w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/Internet-100x3.png 100w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/Internet-700x23.png 700w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/Internet.png 1328w\" data-sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/a><br \/>\n5. Test your setup with the following CLI command:<br \/>\n<code>show routing fib virtual-router default ecmp yes<\/code><br \/>\nWhere &#8220;default&#8221; is the name of your Virtual Router. You should see the hit column increment evenly across the two links for the same path as below:<br \/>\n<a href=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/vr.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.insecurewi.re\/wp-content\/themes\/breek\/assets\/images\/transparent.gif\" data-lazy=\"true\" data-src=\"https:\/\/www.insecurewire.com\/wp-content\/uploads\/2020\/03\/vr.png\" alt=\"Virtual Router\" width=\"775\" height=\"363\" class=\"aligncenter size-full wp-image-561\" data-srcset=\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/vr.png 775w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/vr-300x141.png 300w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/vr-768x360.png 768w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/vr-100x47.png 100w, https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/vr-700x328.png 700w\" data-sizes=\"auto, (max-width: 775px) 100vw, 775px\" \/><\/a><\/p>\n<p>As many Australian IT professionals would know, NBN FTTN is a lottery. If you are more 500m away from a Node then the VDSL signal degrades. If the copper was existing then your really out of luck because its not just the distance, old copper and DSL don&#8217;t mix. In our case we are 400-600m away from the nodes and the copper was of OK quality. I did use L2 VLANs to link the MDF location back to the firewall so that I didn&#8217;t add L1 copper distance, which would effect the VDSL2 signal. With these locations now that we have 2 x VDSL circuits per site and they are session load balanced with ECMP and the PA firewalls we are seeing about double effective throughput. Approx 135\/45 and 110\/40 speeds using fast.com.<\/p>\n<p>Palo Alto also have a really good KA for this configuration which is located <a href=\"https:\/\/knowledgebase.paloaltonetworks.com\/KCSArticleDetail?id=kA10g000000ClF8CAK\" rel=\"noopener noreferrer\" target=\"_blank\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have multiple campuses that are in Fibre to the Node NBN service areas. The cost to upgrade these campuses to full fibre starts at&#8230;<\/p>\n","protected":false},"author":2,"featured_media":573,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36,5],"tags":[94,134,139],"class_list":["post-543","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nbn","category-palo-alto-networks","tag-ecmp","tag-nbn","tag-palo-alto"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Configuring ECMP on Palo Alto Firewalls with FTTN NBN - Insecure Wire<\/title>\n<meta name=\"description\" content=\"We have multiple campuses that are in Fibre to the Node NBN service areas. The cost to upgrade these campuses to full fibre starts at around $15k per campus. In lieu of this cost we have rolled out multiple VDSL FTTN connections to each campus that requires more bandwidth.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Configuring ECMP on Palo Alto Firewalls with FTTN NBN - Insecure Wire\" \/>\n<meta property=\"og:description\" content=\"We have multiple campuses that are in Fibre to the Node NBN service areas. The cost to upgrade these campuses to full fibre starts at around $15k per campus. In lieu of this cost we have rolled out multiple VDSL FTTN connections to each campus that requires more bandwidth.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/\" \/>\n<meta property=\"og:site_name\" content=\"Insecure Wire\" \/>\n<meta property=\"article:published_time\" content=\"2020-03-28T17:10:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png\" \/>\n\t<meta property=\"og:image:width\" content=\"948\" \/>\n\t<meta property=\"og:image:height\" content=\"447\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"nikonau\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/insecurewire\" \/>\n<meta name=\"twitter:site\" content=\"@insecurewire\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"nikonau\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/\"},\"author\":{\"name\":\"nikonau\",\"@id\":\"https:\/\/www.insecurewi.re\/#\/schema\/person\/8ba08b41fc754b971a948ead6ccb777d\"},\"headline\":\"Configuring ECMP on Palo Alto Firewalls with FTTN NBN\",\"datePublished\":\"2020-03-28T17:10:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/\"},\"wordCount\":501,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.insecurewi.re\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png\",\"keywords\":[\"ECMP\",\"NBN\",\"Palo Alto\"],\"articleSection\":[\"NBN\",\"Palo Alto Networks\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/\",\"url\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/\",\"name\":\"Configuring ECMP on Palo Alto Firewalls with FTTN NBN - Insecure Wire\",\"isPartOf\":{\"@id\":\"https:\/\/www.insecurewi.re\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png\",\"datePublished\":\"2020-03-28T17:10:48+00:00\",\"description\":\"We have multiple campuses that are in Fibre to the Node NBN service areas. The cost to upgrade these campuses to full fibre starts at around $15k per campus. In lieu of this cost we have rolled out multiple VDSL FTTN connections to each campus that requires more bandwidth.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#primaryimage\",\"url\":\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png\",\"contentUrl\":\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png\",\"width\":948,\"height\":447,\"caption\":\"ECMP Network Diagram\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.insecurewi.re\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Configuring ECMP on Palo Alto Firewalls with FTTN NBN\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.insecurewi.re\/#website\",\"url\":\"https:\/\/www.insecurewi.re\/\",\"name\":\"Insecure Wire\",\"description\":\"A Network Engineer\u2019s Perspective.\",\"publisher\":{\"@id\":\"https:\/\/www.insecurewi.re\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.insecurewi.re\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.insecurewi.re\/#organization\",\"name\":\"Insecure Wire\",\"url\":\"https:\/\/www.insecurewi.re\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.insecurewi.re\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2023\/10\/cloud.png\",\"contentUrl\":\"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2023\/10\/cloud.png\",\"width\":32,\"height\":32,\"caption\":\"Insecure Wire\"},\"image\":{\"@id\":\"https:\/\/www.insecurewi.re\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/insecurewire\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.insecurewi.re\/#\/schema\/person\/8ba08b41fc754b971a948ead6ccb777d\",\"name\":\"nikonau\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.insecurewi.re\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/2d1b9d9dc90da4f6d3da31b870f418c6b3553ba9be48d53e8ee3a35b0adb1d35?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/2d1b9d9dc90da4f6d3da31b870f418c6b3553ba9be48d53e8ee3a35b0adb1d35?s=96&d=mm&r=g\",\"caption\":\"nikonau\"},\"sameAs\":[\"https:\/\/x.com\/https:\/\/twitter.com\/insecurewire\"],\"url\":\"https:\/\/www.insecurewi.re\/index.php\/author\/nikon\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Configuring ECMP on Palo Alto Firewalls with FTTN NBN - Insecure Wire","description":"We have multiple campuses that are in Fibre to the Node NBN service areas. The cost to upgrade these campuses to full fibre starts at around $15k per campus. In lieu of this cost we have rolled out multiple VDSL FTTN connections to each campus that requires more bandwidth.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/","og_locale":"en_US","og_type":"article","og_title":"Configuring ECMP on Palo Alto Firewalls with FTTN NBN - Insecure Wire","og_description":"We have multiple campuses that are in Fibre to the Node NBN service areas. The cost to upgrade these campuses to full fibre starts at around $15k per campus. In lieu of this cost we have rolled out multiple VDSL FTTN connections to each campus that requires more bandwidth.","og_url":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/","og_site_name":"Insecure Wire","article_published_time":"2020-03-28T17:10:48+00:00","og_image":[{"width":948,"height":447,"url":"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png","type":"image\/png"}],"author":"nikonau","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/insecurewire","twitter_site":"@insecurewire","twitter_misc":{"Written by":"nikonau","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#article","isPartOf":{"@id":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/"},"author":{"name":"nikonau","@id":"https:\/\/www.insecurewi.re\/#\/schema\/person\/8ba08b41fc754b971a948ead6ccb777d"},"headline":"Configuring ECMP on Palo Alto Firewalls with FTTN NBN","datePublished":"2020-03-28T17:10:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/"},"wordCount":501,"commentCount":0,"publisher":{"@id":"https:\/\/www.insecurewi.re\/#organization"},"image":{"@id":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#primaryimage"},"thumbnailUrl":"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png","keywords":["ECMP","NBN","Palo Alto"],"articleSection":["NBN","Palo Alto Networks"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/","url":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/","name":"Configuring ECMP on Palo Alto Firewalls with FTTN NBN - Insecure Wire","isPartOf":{"@id":"https:\/\/www.insecurewi.re\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#primaryimage"},"image":{"@id":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#primaryimage"},"thumbnailUrl":"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png","datePublished":"2020-03-28T17:10:48+00:00","description":"We have multiple campuses that are in Fibre to the Node NBN service areas. The cost to upgrade these campuses to full fibre starts at around $15k per campus. In lieu of this cost we have rolled out multiple VDSL FTTN connections to each campus that requires more bandwidth.","breadcrumb":{"@id":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#primaryimage","url":"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png","contentUrl":"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2020\/03\/diagram.png","width":948,"height":447,"caption":"ECMP Network Diagram"},{"@type":"BreadcrumbList","@id":"https:\/\/www.insecurewi.re\/index.php\/2020\/03\/29\/configuring-ecmp-on-palo-alto-firewalls-with-fttn-nbn\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.insecurewi.re\/"},{"@type":"ListItem","position":2,"name":"Configuring ECMP on Palo Alto Firewalls with FTTN NBN"}]},{"@type":"WebSite","@id":"https:\/\/www.insecurewi.re\/#website","url":"https:\/\/www.insecurewi.re\/","name":"Insecure Wire","description":"A Network Engineer\u2019s Perspective.","publisher":{"@id":"https:\/\/www.insecurewi.re\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.insecurewi.re\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.insecurewi.re\/#organization","name":"Insecure Wire","url":"https:\/\/www.insecurewi.re\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.insecurewi.re\/#\/schema\/logo\/image\/","url":"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2023\/10\/cloud.png","contentUrl":"https:\/\/www.insecurewi.re\/wp-content\/uploads\/2023\/10\/cloud.png","width":32,"height":32,"caption":"Insecure Wire"},"image":{"@id":"https:\/\/www.insecurewi.re\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/insecurewire"]},{"@type":"Person","@id":"https:\/\/www.insecurewi.re\/#\/schema\/person\/8ba08b41fc754b971a948ead6ccb777d","name":"nikonau","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.insecurewi.re\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/2d1b9d9dc90da4f6d3da31b870f418c6b3553ba9be48d53e8ee3a35b0adb1d35?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2d1b9d9dc90da4f6d3da31b870f418c6b3553ba9be48d53e8ee3a35b0adb1d35?s=96&d=mm&r=g","caption":"nikonau"},"sameAs":["https:\/\/x.com\/https:\/\/twitter.com\/insecurewire"],"url":"https:\/\/www.insecurewi.re\/index.php\/author\/nikon\/"}]}},"_links":{"self":[{"href":"https:\/\/www.insecurewi.re\/index.php\/wp-json\/wp\/v2\/posts\/543","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insecurewi.re\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insecurewi.re\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insecurewi.re\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insecurewi.re\/index.php\/wp-json\/wp\/v2\/comments?post=543"}],"version-history":[{"count":0,"href":"https:\/\/www.insecurewi.re\/index.php\/wp-json\/wp\/v2\/posts\/543\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insecurewi.re\/index.php\/wp-json\/wp\/v2\/media\/573"}],"wp:attachment":[{"href":"https:\/\/www.insecurewi.re\/index.php\/wp-json\/wp\/v2\/media?parent=543"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insecurewi.re\/index.php\/wp-json\/wp\/v2\/categories?post=543"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insecurewi.re\/index.php\/wp-json\/wp\/v2\/tags?post=543"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}