<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBF with ECMP Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-ecmp-issue/m-p/502980#M105386</link>
    <description>&lt;P&gt;For first deployment we was setting to ECMP because they want to utilize all the WAN Links, after few weeks our user had a problem with routing,so we check the routing and see if any problem but we don't find that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we use the NAT and PBF to specify some segment to specific WAN link, and let the other segment use the ECMP Configuration. I Check another threat in palo/others vendors, i think this is the behaviour the ECMP configuration, balancing the traffic, even we specify the link and when the link is higher than the other, the configuration is balancing the link.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jun 2022 02:54:29 GMT</pubDate>
    <dc:creator>DennyChanditya</dc:creator>
    <dc:date>2022-06-13T02:54:29Z</dc:date>
    <item>
      <title>PBF with ECMP Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-ecmp-issue/m-p/488978#M104861</link>
      <description>&lt;P&gt;Hello, i have question about PBF Using ECMP.&lt;/P&gt;&lt;P&gt;We have 3 ISP and using ECMP Setting with weight round robin and Symetric Return Settings&lt;/P&gt;&lt;P&gt;ISP A &amp;gt; 200&lt;/P&gt;&lt;P&gt;ISP B &amp;gt; 100&lt;/P&gt;&lt;P&gt;ISP C &amp;gt; 50&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT we set like this&lt;/P&gt;&lt;P&gt;All&amp;nbsp; User &amp;gt; ISP A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using PBF for some IP Segment&lt;/P&gt;&lt;P&gt;Segment A to ISP A&lt;/P&gt;&lt;P&gt;Segment B to ISP B&lt;/P&gt;&lt;P&gt;Segment C to ISP C&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But we have some problem link below :&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we check the traffic monitor, we can see that IP Segment A is still Going to ISP B and ISP C&lt;/P&gt;&lt;P&gt;When we disable ECMP, setting the ISP metric in virtual routing to 10,20,30, the Globalprotect only up for ISP that have a low metric.&lt;/P&gt;&lt;P&gt;For some reason, some users can't access/maybe have a slower access to specific website.&lt;/P&gt;&lt;P&gt;Security policy for now we set to Allow All.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any solution to avoid IP Segment A going to ISP B and C using this ECMP Method?&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 15:48:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-ecmp-issue/m-p/488978#M104861</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2022-05-20T15:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: PBF with ECMP Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-ecmp-issue/m-p/502115#M105291</link>
      <description>&lt;P&gt;I may be missing the point, but why do you enable ECMP if you only set NAT for ISP A and then set PBF policies to send traffic to a certain ISP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i bet you're running into some sort of conflict where ECMP is bouncing users off to ISP B+C (because you defined ECMP)&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 09:09:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-ecmp-issue/m-p/502115#M105291</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2022-06-09T09:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: PBF with ECMP Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-ecmp-issue/m-p/502980#M105386</link>
      <description>&lt;P&gt;For first deployment we was setting to ECMP because they want to utilize all the WAN Links, after few weeks our user had a problem with routing,so we check the routing and see if any problem but we don't find that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we use the NAT and PBF to specify some segment to specific WAN link, and let the other segment use the ECMP Configuration. I Check another threat in palo/others vendors, i think this is the behaviour the ECMP configuration, balancing the traffic, even we specify the link and when the link is higher than the other, the configuration is balancing the link.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 02:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-ecmp-issue/m-p/502980#M105386</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2022-06-13T02:54:29Z</dc:date>
    </item>
  </channel>
</rss>

