Configuring primary and secondary tunnel interfaces

On your Palo Alto edge device, configure two tunnel interfaces for primary and secondary connections.

Steps

  1. Navigate to Network > Interfaces > Tunnel > Add.
    For example:


  2. Configure the tunnel ID by entering a numeric suffix in Interface Name.
    For example:
    • For primary tunnel, enter 1
    • For secondary tunnel, enter 2
  3. On the Config tab, configure appropriate Virtual Router and Security Zone based on the network settings.
    In this example, tunnel interface and the egress interface are configured in the same virtual router and security zone.
  4. On the IPv4 tab, configure an IPv4 address.
    This can be any IPv4 address. Make sure that it does not overlap with any other subnets in the network.
  5. To save the tunnel interface, click OK.
  6. Repeat step (1) through step (5) to create secondary tunnel interface.
    For example:


Result

You have primary and secondary tunnel interfaces. In this example, tunnel.1 represents primary tunnel interface and tunnel.2 represents secondary tunnel interface.