<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does PBF rule works for traffic originating from Global Protect Client in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-pbf-rule-works-for-traffic-originating-from-global-protect/m-p/440566#M1875</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two Global Protect portals/Gateways configured on each firewall ISP 1(Eth 1/1) and ISP 2(Eth 1/2) interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had enabled ECMP on the firewall with max path 2 and configured ISP 1 and ISP 2 as default routes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When an user is connected to GP configured on ISP 2 interface and trying to access internet the traffic from GP client is routed through ISP 1 interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As ECMP is configured this is an expected behaviour.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we use an PBF rule to route the traffic originating from end user GP Client to go through an particular interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the below article it is mentioned that Global protect traffic cannot be routed using PBF policy. Is it also applicable for the traffic originating from GP client end user system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbDCAS#:~:text=PBF%20does%20not%20function%20for%20GlobalProtect%20connection" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbDCAS#:~:text=PBF%20does%20not%20function%20for%20GlobalProtect%20connection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Oct 2021 15:10:26 GMT</pubDate>
    <dc:creator>tamilvanan</dc:creator>
    <dc:date>2021-10-13T15:10:26Z</dc:date>
    <item>
      <title>Does PBF rule works for traffic originating from Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-pbf-rule-works-for-traffic-originating-from-global-protect/m-p/440566#M1875</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two Global Protect portals/Gateways configured on each firewall ISP 1(Eth 1/1) and ISP 2(Eth 1/2) interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had enabled ECMP on the firewall with max path 2 and configured ISP 1 and ISP 2 as default routes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When an user is connected to GP configured on ISP 2 interface and trying to access internet the traffic from GP client is routed through ISP 1 interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As ECMP is configured this is an expected behaviour.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we use an PBF rule to route the traffic originating from end user GP Client to go through an particular interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the below article it is mentioned that Global protect traffic cannot be routed using PBF policy. Is it also applicable for the traffic originating from GP client end user system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbDCAS#:~:text=PBF%20does%20not%20function%20for%20GlobalProtect%20connection" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbDCAS#:~:text=PBF%20does%20not%20function%20for%20GlobalProtect%20connection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 15:10:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-pbf-rule-works-for-traffic-originating-from-global-protect/m-p/440566#M1875</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-10-13T15:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Does PBF rule works for traffic originating from Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-pbf-rule-works-for-traffic-originating-from-global-protect/m-p/441353#M1884</link>
      <description>&lt;P&gt;Play arround. You can use the option to add the VPN traffic to a specific zone for more easilly manage it with PBF:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/get-started/create-interfaces-and-zones-for-globalprotect.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/get-started/create-interfaces-and-zones-for-globalprotect.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 11:59:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-pbf-rule-works-for-traffic-originating-from-global-protect/m-p/441353#M1884</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-10-17T11:59:43Z</dc:date>
    </item>
  </channel>
</rss>

