20-Virtual Routers (VR)
20-Virtual Routers (VR)
o When it comes to routing traffic between different networks one needs a Router.
o Palo Alto Networks Firewalls are capable of routing the traffic between networks.
o Uses concept of “Virtual Routers” to route traffic be it static or dynamic routing.
o Virtual Router uses virtualized or partitioned routing tables to do the routing job.
o Uses virtual routers to obtain routes & uses best route to populates its routing table.
o PA Firewall capable of supporting Dynamic routing protocols like RIPv2, OSPF & BGPv4.
o The Palo Alto NG Network Firewalls comes with a Virtual router named the default.
o Can be used for routing provided layer3 interfaces or VLANs are part of that default VR.
o Can also create new Virtual Router & name & use it for both static & dynamic routing.
o In Palo Alto Firewall Layer 3 deployment, the Firewall routes traffic between ports.
o Each L3, loopback interface, & VLAN interface must be associated with Virtual Router.
o In Palo Alto Network Firewall each interface can belong to only one Virtual Router.
o IP must be assigned to each interface & virtual router must be defined to route traffic.
o PA Firewall can create multiple virtual routers, each maintaining separate set of routes.
o An Addition to adding static routes, can configure to participate with dynamic routing.
o Virtual Routers used for Layer 3 IP routing and also supports one or more static routes.
Settings Description
Name Specify a name to describe the Virtual Router.
Interfaces Select the interfaces that want to include in the Virtual Router.
Administrative Distances Specify the Administrative Distances.
Administrative Distances
Static Routes Range is 10-240 Default is 10
OSPF Internal Range is 10-240 Default is 30
OSPF External Range is 10-240 Default is 110
IBGP Range is 10-240 Default is 200
EBGP Range is 10-240 Default is 20
RIP Range is 10-240 Default is 120
Network -> Virtual Routers -> Add Type name “VR-WAN” -> click OK