<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Policy-Based Forwarding Symmetric Return Overview in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/policy-based-forwarding-symmetric-return-overview/ta-p/545067</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG style="box-sizing: inherit; color: #1d1c1d; font-family: Slack-Lato, Slack-Fractions, appleLogo, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: common-ligatures; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #f8f8f8; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" data-stringify-type="bold"&gt;&lt;I data-stringify-type="italic"&gt;This article was created by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163113"&gt;@aalex&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Enabling symmetric return ensures that return traffic is forwarded out through the same interface through which traffic ingresses. This feature is useful when the requirement is to access servers through two ISP connections (on different ingress interfaces) and the return traffic must be routed through the ISP that originally routed the sessions.&lt;/SPAN&gt;&lt;BR style="box-sizing: border-box; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;This feature is also required for asymmetric routing environments.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The feature is configured under&lt;EM&gt; Policies &amp;gt; Policy Base Forwarding &amp;gt; Open an existing rule&lt;STRONG&gt;, &lt;/STRONG&gt;or click &lt;STRONG&gt;Add&lt;/STRONG&gt; to create a new one &amp;gt; Forwarding&lt;/EM&gt;. Tick the &lt;STRONG&gt;Enforce Symmetric Return&lt;/STRONG&gt; button &lt;/SPAN&gt;&lt;SPAN&gt;to enable the feature.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR style="box-sizing: border-box; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;Note: If the client-to-server traffic does not need to be forwarded to a specific egress interface or next hop then the &lt;EM&gt;Forwarding &amp;gt; Action&lt;/EM&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;can be set to &lt;STRONG&gt;No PBF&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; This prevents the alteration of the path that the client-to-server packets take, which lets the matching client-to-server packets use the normal route table path while the server-to-client packets still benefit from the symmetric return feature.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR style="box-sizing: border-box; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;Things to keep in mind regarding next hop addresses:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL style="box-sizing: border-box; margin: 0px 0px 0.75rem 1.5rem; padding: 0px; list-style: disc; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;Configuring next hop addresses in the Next Hop Address List is optional, but forwarding may fail when Enforce Symmetric Return is enabled without a next hop address. Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A style="box-sizing: border-box; color: #0070d2; background-color: transparent; cursor: pointer; outline: none; text-decoration: none; transition: color 0.1s linear 0s; touch-action: manipulation;" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5gCAC" target="_blank" rel="noopener"&gt;here&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;for more details.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;Up to 8 next hop addresses can be defined per PBF rule.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;PBF rules will not use the symmetric return option if the packet's source IP address is in the same subnet as the symmetric return address.&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditorkiwi_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorkiwi_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="kiwi_3-1686129028146.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50697i7EE5E6FC08947FEB/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_3-1686129028146.png" alt="kiwi_3-1686129028146.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The following command can be used to monitor the return-mac entry table:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@VM-1&amp;gt; show pbf return-mac all

current pbf configuation version:   1
total return nexthop addresses :    0

index   pbf id  ver  hw address          ip address                                                  
                     return mac          egress port
--------------------------------------------------------------------------------

maximum of ipv4 return mac entries supported :     1250
total ipv4 return mac entries in table :           0
total ipv4 return mac entries shown :              0
status: s - static, c - complete, e - expiring, i - incomplete

pbf rule        id   ip address      hw address        port         status   ttl                      
--------------------------------------------------------------------------------

maximum of ipv6 return mac entries supported :     500
total ipv6 return mac entries in table :           0
total ipv6 return mac entries shown :              0
status: s - static, c - complete, e - expiring, i - incomplete

pbf rule        id   ip address                              hw address        status
--------------------------------------------------------------------------------&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px 0px 0.75rem; padding: 0px; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&lt;FONT size="3"&gt;This return-mac table can be cleared manually with the following commands:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px 0px 0.75rem; padding: 0px; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px 0px 0.75rem; padding: 0px; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; clear pbf return-mac name &amp;lt;value&amp;gt;
or
&amp;gt; clear pbf return-mac all&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px 0px 0.75rem; padding: 0px; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px 0px 0.75rem; padding: 0px; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&lt;FONT size="3"&gt;Notes regarding the return-mac table:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL style="box-sizing: border-box; margin: 0px 0px 0.75rem 1.5rem; padding: 0px; list-style: disc; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;The return-mac table size is always half of the ARP table entry size based on the firewall model. This capacity applies per device and is not limited per vsys.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;The displayed entries in the table, as well as the total entries counter, only show the information from the current vsys.&lt;/FONT&gt;
&lt;UL style="box-sizing: border-box; margin: 0px 0px 0.75rem 1.5rem; padding: 0px; list-style: circle;"&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;To change the vsys information being displayed, change to a different vsys and re-run the command:&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; set system setting target-vsys &amp;lt;vsys-name&amp;gt;
once done, set it back
&amp;gt; set system setting target-vsys none&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL style="box-sizing: border-box; margin: 0px 0px 0.75rem 1.5rem; padding: 0px; list-style: disc; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;The unused entries remain in the table for 30 minutes before getting timed out and flushed automatically.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;If a symmetric return next hop address is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM style="box-sizing: border-box;"&gt;not&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;configured, then the packet's source MAC address is used as the return-mac.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;If a symmetric return next hop address is configured, then the packet's source MAC address is also used as the return-mac, but if the return-mac table reaches 80% of its capacity then new return-mac entries are no longer populated in that table and the return-mac falls back to using the configured next hop's MAC address.&lt;/FONT&gt;
&lt;UL style="box-sizing: border-box; margin: 0px 0px 0.75rem 1.5rem; padding: 0px; list-style: circle;"&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;If there are multiple IP addresses configured in the Next Hop Address List then the first one that is accessible (ARP resolved) will be selected as the next hop.&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;There are no logs/alerts triggered once the return-mac entries threshold is reached.&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The following should also be noted when using the symmetric return feature:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL style="box-sizing: border-box; margin: 0px 0px 0.75rem 1.5rem; padding: 0px; list-style: disc; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM style="box-sizing: border-box;"&gt;Source &amp;gt; Type&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of the PBF rule must be an interface, not a zone.&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="kiwi_4-1686129261081.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50698iEB3497FCA2140FB0/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_4-1686129261081.png" alt="kiwi_4-1686129261081.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL style="box-sizing: border-box; margin: 0px 0px 0.75rem 1.5rem; padding: 0px; list-style: disc; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;The symmetric return option can be used for all Layer-3 interfaces, except loopback interfaces. It is also supported for interfaces that have the IP address assigned dynamically (DHCP and PPoE).&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;The next hop address list is not supported for tunnel and PPoE interfaces.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;If an interface has multiple PBF rules, only one rule can enforce symmetric return.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="box-sizing: border-box; margin-left: 0px; padding-left: 0px;"&gt;&lt;FONT size="3"&gt;If the same source IP address is expected to come in from different ingress interfaces, then the return traffic for this client may flap in between the ingress interfaces when hardware offloading is involved. It is suggested to configure separate symmetric-return PBF rules for each ingress interface to avoid this.&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN class="fieldLabel"&gt;Additional Information&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;BR style="box-sizing: border-box; color: #16325c; font-family: 'Salesforce Sans', Arial, sans-serif; font-size: 11.375px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;Additional details about Symmetric Return configuration with examples can be found&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A style="box-sizing: border-box; color: #0070d2; background-color: transparent; cursor: pointer; outline: none; text-decoration: none; transition: color 0.1s linear 0s; touch-action: manipulation;" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF5CAK" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2023 18:15:34 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2023-06-07T18:15:34Z</dc:date>
    <item>
      <title>Policy-Based Forwarding Symmetric Return Overview</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/policy-based-forwarding-symmetric-return-overview/ta-p/545067</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Enabling symmetric return ensures that return traffic is forwarded out through the same interface through which traffic ingresses. This feature is useful when the requirement is to access servers through two ISP connections (on different ingress interfaces) and the return traffic must be routed through the ISP that originally routed the sessions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 18:15:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/policy-based-forwarding-symmetric-return-overview/ta-p/545067</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-06-07T18:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Policy-Based Forwarding Symmetric Return Overview</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/policy-based-forwarding-symmetric-return-overview/tac-p/596602#M746</link>
      <description>&lt;P&gt;What happens if you use Source Zone instead of Source Interface while enabling Symmetric Return?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 10:41:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/policy-based-forwarding-symmetric-return-overview/tac-p/596602#M746</guid>
      <dc:creator>FrancisMatutes</dc:creator>
      <dc:date>2024-09-03T10:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Policy-Based Forwarding Symmetric Return Overview</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/policy-based-forwarding-symmetric-return-overview/tac-p/1238582#M833</link>
      <description>&lt;P&gt;PPPoE 回線に PBR の 'symmetric return' を指定する場合、next-hop アドレスを指定できません。&lt;BR /&gt;対向機器は ISP のルーター 1台でも return-mac table の溢れに注意する必要がありますか？&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 15:48:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/policy-based-forwarding-symmetric-return-overview/tac-p/1238582#M833</guid>
      <dc:creator>FFEEC73E3F24854683C8C9</dc:creator>
      <dc:date>2025-09-23T15:48:59Z</dc:date>
    </item>
  </channel>
</rss>

