<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Destination Zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/destination-zone/m-p/460042#M102031</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found in documentation : "Assign destination zone based on Interface packet would egress from"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is behind this "would" ? How is choose the destination zone , based on FW topology or routing table or ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set a route (next hop Tunnel interface) to a subnet and a NAT rule.&lt;/P&gt;&lt;P&gt;I have a traffic from 2 differents source zone but same destination.&lt;/P&gt;&lt;P&gt;In log, destination zone is not the same for each traffic;&lt;/P&gt;&lt;P&gt;My rules are working but I can't explain why.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So how is based the choice for the destination zone ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jan 2022 06:02:23 GMT</pubDate>
    <dc:creator>didier.bonato</dc:creator>
    <dc:date>2022-01-21T06:02:23Z</dc:date>
    <item>
      <title>Destination Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-zone/m-p/460042#M102031</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found in documentation : "Assign destination zone based on Interface packet would egress from"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is behind this "would" ? How is choose the destination zone , based on FW topology or routing table or ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set a route (next hop Tunnel interface) to a subnet and a NAT rule.&lt;/P&gt;&lt;P&gt;I have a traffic from 2 differents source zone but same destination.&lt;/P&gt;&lt;P&gt;In log, destination zone is not the same for each traffic;&lt;/P&gt;&lt;P&gt;My rules are working but I can't explain why.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So how is based the choice for the destination zone ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 06:02:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-zone/m-p/460042#M102031</guid>
      <dc:creator>didier.bonato</dc:creator>
      <dc:date>2022-01-21T06:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: Destination Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-zone/m-p/460269#M102050</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;As for the logs, enable logging at session end on all polcies and then check the traffic logs to see what they say. As for egress zone, its where the traffic is going or where it will end up. Each interface must be assigned a zone, where the packets leaves the firewall interface, that would be the egress zone based on the interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 19:27:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-zone/m-p/460269#M102050</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-01-21T19:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Destination Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-zone/m-p/460496#M102083</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;BR /&gt;My question is not : how i can check the destination zone but how PAN OS set it ?&lt;/P&gt;&lt;P&gt;After checking routing table or depending on the topology of firewall or something else ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 07:57:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-zone/m-p/460496#M102083</guid>
      <dc:creator>didier.bonato</dc:creator>
      <dc:date>2022-01-24T07:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Destination Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-zone/m-p/460570#M102090</link>
      <description>&lt;P&gt;Destination zone is decided based on routes in virtual router so yes routing table.&lt;/P&gt;&lt;P&gt;If you have Policy Based Forwarding rules that overlap with virtual router then PBF route will take precedence over virtual router.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 14:09:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-zone/m-p/460570#M102090</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2022-01-24T14:09:27Z</dc:date>
    </item>
  </channel>
</rss>

