<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBF Rule Monitoring - Forced egress i/f? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pbf-rule-monitoring-forced-egress-i-f/m-p/573809#M2491</link>
    <description>&lt;P&gt;Rule state "Disabled" means that monitoring took PBF down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To troubleshoot:&lt;/P&gt;
&lt;P&gt;Uncheck "Disable this rule if nexthop/monitor ip is unreachable" to force PBF to be active.&lt;BR /&gt;Generate some traffic that matches PBF.&lt;BR /&gt;Go to Monitor &amp;gt; Traffic and check logs.&lt;BR /&gt;Did traffic flow work?&lt;BR /&gt;Did you get any replies from ethernet1/2?&lt;BR /&gt;Do you have source nat policy configured for traffic exiting ethernet1/2 interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you get traffic working then you can re-check "Disable this rule if nexthop/monitor ip is unreachable" checkbox to enable PBF rule monitoring.&lt;/P&gt;</description>
    <pubDate>Sun, 21 Jan 2024 13:38:37 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2024-01-21T13:38:37Z</dc:date>
    <item>
      <title>PBF Rule Monitoring - Forced egress i/f?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pbf-rule-monitoring-forced-egress-i-f/m-p/573791#M2489</link>
      <description>&lt;P&gt;I have a dual ISP configuration.&amp;nbsp; ethernet1/1 is primary Internet.&amp;nbsp; ethernet1/2 is backup wireless Internet (phone or dedicated hot spot as needed).&amp;nbsp; ethernet1/2 is connected to an old Linksys router running DD-WRT and it automatically connects to my hotspot when I turn it on.&amp;nbsp; Otherwise, there is no Internet access via ethernet1/2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a PBF rule configured with an egress interface of ethernet1/2, a next hop of 192.168.2.1, and a monitor configured for 8.8.4.4.&amp;nbsp; Obviously 8.8.4.4 is pingable from any internal network client as it is using ethernet1/1 for Internet access.&amp;nbsp; However, running &lt;STRONG&gt;show pdf rule all&lt;/STRONG&gt; shows the PBF rule state as Disabled instead of Active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only documentation I can find on Path monitoring for PBF is:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/policy-based-forwarding/pbf/path-monitoring-for-pbf" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/policy-based-forwarding/pbf/path-monitoring-for-pbf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It does not say that the monitor doesn't follow routing rules and instead forces out the egress interface.&amp;nbsp; It also doesn't say anything about the next hop being used.&amp;nbsp; I'm presuming at this point that the egress interface and/or next hop configuration on the Forwarding tab of the PBF rule play a role in how the monitor operates, but I would like to find some official documentation that can support the theory, especially if the theory is wrong and this is working by accident or some other function.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bottom line: Why is this working?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2024 17:35:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pbf-rule-monitoring-forced-egress-i-f/m-p/573791#M2489</guid>
      <dc:creator>jhossbach</dc:creator>
      <dc:date>2024-01-20T17:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Rule Monitoring - Forced egress i/f?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pbf-rule-monitoring-forced-egress-i-f/m-p/573809#M2491</link>
      <description>&lt;P&gt;Rule state "Disabled" means that monitoring took PBF down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To troubleshoot:&lt;/P&gt;
&lt;P&gt;Uncheck "Disable this rule if nexthop/monitor ip is unreachable" to force PBF to be active.&lt;BR /&gt;Generate some traffic that matches PBF.&lt;BR /&gt;Go to Monitor &amp;gt; Traffic and check logs.&lt;BR /&gt;Did traffic flow work?&lt;BR /&gt;Did you get any replies from ethernet1/2?&lt;BR /&gt;Do you have source nat policy configured for traffic exiting ethernet1/2 interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you get traffic working then you can re-check "Disable this rule if nexthop/monitor ip is unreachable" checkbox to enable PBF rule monitoring.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 13:38:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pbf-rule-monitoring-forced-egress-i-f/m-p/573809#M2491</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-01-21T13:38:37Z</dc:date>
    </item>
  </channel>
</rss>

