<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PBF Rules being ignored in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rules-being-ignored/m-p/511581#M106351</link>
    <description>&lt;P&gt;I have setup several PBFs to force traffic to use a specific egress interface for monitoring that particular path.&amp;nbsp; I then setup a ping monitor on one of the servers, Source Address 192.168.200.15, to ping several different Destination Addresses (DA).&amp;nbsp; The SA is the same for each 'monitor' but the DA is different.&amp;nbsp; The PBF is then setup to forward this traffic based on the source and destination addresses to the interface I want to monitor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The rules look something like this:&lt;BR /&gt;Rule1. PBF_Egress-1 SA:192.168.200.15 DA:4.2.2.1 Action:Forward Egress-I/F:Eth1/1 Next Hop:192.168.0.1&lt;/P&gt;
&lt;P&gt;Rule2. PBF_Egress-2 SA:192.168.200.15 DA:4.2.2.2 Action:Forward Egress-I/F:Eth1/2 Next Hop:192.168.1.1&lt;/P&gt;
&lt;P&gt;Rule3. PBF_Egress-3 SA:192.168.200.15 DA:4.2.2.3 Action:Forward Egress-I/F:Eth1/3 Next Hop:192.168.2.1&lt;/P&gt;
&lt;P&gt;Rule4. PBF_Egress-4 SA:192.168.200.15 DA:4.2.2.4 Action:Forward Egress-I/F:Eth1/4 Next Hop:192.168.3.1&lt;/P&gt;
&lt;P&gt;Rule5. PBF_Egress-Block SA:192.168.200.15 DA:&amp;lt;all of the above DAs&amp;gt;&amp;nbsp;Action:discard&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rule 5 is in place to make sure that if the traffic gets past those monitor PBF rules 1-4 it is discarded so that it can't use the default routes.&amp;nbsp; I just setup a new rule and the interface is still not active so I would expect that the traffic to not be forwarded because it should still be handled by the new rule, rule 4 or at the very least rule 5, but even though the route is not yet valid but it seems to be making it past all of these rules to the default route rule and getting forwarded.&amp;nbsp; When I verify the traffic via Trace Route from the above SA to 4.2.2.4 I can see that the new traffic is bouncing around the other interfaces and that tells me it's making it to the default routing rules that are a load balanced SD-WAN interface.&amp;nbsp; Those default routing rules are much lower in the stack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone have any ideas why this is happening and how to make sure the PBF rules are honored?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Aug 2022 17:01:34 GMT</pubDate>
    <dc:creator>rmcrae</dc:creator>
    <dc:date>2022-08-11T17:01:34Z</dc:date>
    <item>
      <title>PBF Rules being ignored</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rules-being-ignored/m-p/511581#M106351</link>
      <description>&lt;P&gt;I have setup several PBFs to force traffic to use a specific egress interface for monitoring that particular path.&amp;nbsp; I then setup a ping monitor on one of the servers, Source Address 192.168.200.15, to ping several different Destination Addresses (DA).&amp;nbsp; The SA is the same for each 'monitor' but the DA is different.&amp;nbsp; The PBF is then setup to forward this traffic based on the source and destination addresses to the interface I want to monitor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The rules look something like this:&lt;BR /&gt;Rule1. PBF_Egress-1 SA:192.168.200.15 DA:4.2.2.1 Action:Forward Egress-I/F:Eth1/1 Next Hop:192.168.0.1&lt;/P&gt;
&lt;P&gt;Rule2. PBF_Egress-2 SA:192.168.200.15 DA:4.2.2.2 Action:Forward Egress-I/F:Eth1/2 Next Hop:192.168.1.1&lt;/P&gt;
&lt;P&gt;Rule3. PBF_Egress-3 SA:192.168.200.15 DA:4.2.2.3 Action:Forward Egress-I/F:Eth1/3 Next Hop:192.168.2.1&lt;/P&gt;
&lt;P&gt;Rule4. PBF_Egress-4 SA:192.168.200.15 DA:4.2.2.4 Action:Forward Egress-I/F:Eth1/4 Next Hop:192.168.3.1&lt;/P&gt;
&lt;P&gt;Rule5. PBF_Egress-Block SA:192.168.200.15 DA:&amp;lt;all of the above DAs&amp;gt;&amp;nbsp;Action:discard&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rule 5 is in place to make sure that if the traffic gets past those monitor PBF rules 1-4 it is discarded so that it can't use the default routes.&amp;nbsp; I just setup a new rule and the interface is still not active so I would expect that the traffic to not be forwarded because it should still be handled by the new rule, rule 4 or at the very least rule 5, but even though the route is not yet valid but it seems to be making it past all of these rules to the default route rule and getting forwarded.&amp;nbsp; When I verify the traffic via Trace Route from the above SA to 4.2.2.4 I can see that the new traffic is bouncing around the other interfaces and that tells me it's making it to the default routing rules that are a load balanced SD-WAN interface.&amp;nbsp; Those default routing rules are much lower in the stack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone have any ideas why this is happening and how to make sure the PBF rules are honored?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 17:01:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rules-being-ignored/m-p/511581#M106351</guid>
      <dc:creator>rmcrae</dc:creator>
      <dc:date>2022-08-11T17:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Rules being ignored</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rules-being-ignored/m-p/511765#M106369</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;PBF policies take effect prior to the default router so they are honored first. I say take a look at the traffic logs and make sure the PBF policies match what the traffic logs are seeing, i.e. source/dest/zones/ etc.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 18:51:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rules-being-ignored/m-p/511765#M106369</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-08-12T18:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Rules being ignored</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rules-being-ignored/m-p/511792#M106373</link>
      <description>&lt;P&gt;This problem still exists.&amp;nbsp; I even checked the PBF with the Test Policy Match and according to the test results it is working as expected but when I run a trace route traffic is still passing from the server to the DA that should not be reachable since that path is down.&amp;nbsp; So I can't explain what is causing this and before I turn up that path I'd like to understand what's happening.&amp;nbsp; I've compared the rules to each other and all of the options are the same.&amp;nbsp; The only differences are the DA, Egress Interface, and Next Hop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I should also mention that Rule 5 is only a safety net rule.&amp;nbsp; As long as that rule has been in place it has never received any hits under the Hit Counter.&amp;nbsp; I realize that it's not really needed but at the same time it's not hurting anything either.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 22:20:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rules-being-ignored/m-p/511792#M106373</guid>
      <dc:creator>rmcrae</dc:creator>
      <dc:date>2022-08-12T22:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Rules being ignored</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rules-being-ignored/m-p/573116#M115270</link>
      <description>&lt;P&gt;Still have this issue.&amp;nbsp; PBFs are not honored.&amp;nbsp; I might have to open a case for this.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 05:52:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rules-being-ignored/m-p/573116#M115270</guid>
      <dc:creator>rmcrae</dc:creator>
      <dc:date>2024-01-16T05:52:36Z</dc:date>
    </item>
  </channel>
</rss>

