(PAN-OS 9.1.4 and later 9.1 releases,
and SD-WAN Plugin 1.0.4 and later 1.0 releases) When you start
with these releases, for any new or previously existing VPN cluster
that has more than one hub, in the Gateways window you must prioritize
the hubs to determine that traffic be sent to a particular hub and
to determine the subsequent hub failover order. A cluster supports
a maximum of four hubs. Select a hub and click in the Hub
Failover Priority field. Enter a priority (range is 1
to 4) of the hub. If you upgrade to these releases, the default
priority is set to 4. The plugin internally maps the priority
to a BGP local preference value; the lower the priority value, the
higher the priority and local preference. - Priority 1
maps to local preference 250.
- Priority 2 maps to local preference 200.
- Priority 3 maps to local preference 150.
- Priority 4 maps to local preference 100.
Multiple
hubs can have the same priority; an HA pair must have the same priority.
Panorama uses the branch’s BGP template to push the local preference
of the hubs to the branches in the cluster. If multiple hubs
in the cluster have the same priority, Panorama enables ECMP in
two places on each branch firewall to determine how branches select the
path. ECMP is enabled for the virtual router ()
and ECMP Multiple AS Support is enabled for
BGP ().
If all hubs in the cluster have a unique priority, ECMP is disabled
on the branches. |