<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Based Forwarding is not working for Secondary ISP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-is-not-working-for-secondary-isp/m-p/519244#M107668</link>
    <description>&lt;P&gt;Thanks for your reply.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. The single server doesn't have internet connectivity. It can still talk to the other servers on the LAN but it doesn't have internet connectivity.&lt;/P&gt;
&lt;P&gt;2. Captures show that ARP requests are incomplete. This could be due to the fact that there is no VR configured for ISP2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt;show arp all &lt;BR /&gt;ethernet1/10 147.129.178.129 (incomplete) ethernet1/10 i 1&lt;/P&gt;
&lt;P&gt;&amp;gt;show counter global filter packet-filter yes delta yes severity drop&lt;BR /&gt;flow_fwd_l3_noarp 7 0 drop flow forward Packets dropped: no ARP&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Oct 2022 14:48:04 GMT</pubDate>
    <dc:creator>Anees10</dc:creator>
    <dc:date>2022-10-26T14:48:04Z</dc:date>
    <item>
      <title>Policy Based Forwarding is not working for Secondary ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-is-not-working-for-secondary-isp/m-p/519167#M107660</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Drawing1.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44880i78E33258E59B4989/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Drawing1.png" alt="Drawing1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;We recently added a new Internet link to our PA-3020. We want only one server (10.1.12.130) to use it, so we configured the new internet link interface as layer-3 , assigned it a static IP, created a PBF policy that basically specifies the zone (internal) and the source IP (10.1.12.130) and the destination is any (negate 10.0.0.0/8) and the action is to forward traffic to egress IF 1/10 with next hop of 1.1.1.1&lt;/P&gt;
&lt;P&gt;We also created a NAT rule : From internal zone to external zone, source IF 1/10 and source translation is dynamic-ip-and-port.&lt;/P&gt;
&lt;P&gt;Finally, we created a security policy to allow traffic from that source to the internet.&lt;/P&gt;
&lt;P&gt;We have one virtual route for the old ISP. It's my understanding that no VR is required when using PBF as no failover or redundancy is required between the two links.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The source server doesn't have internet connectivity. FW's Software Version is 9.1.14-h4. We don't use Panorama to manage it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found a similar KB for reference :&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRzCAK#:~:text=Policy%20based%20forwarding%20allows%20you,to%20tweak%20the%20routing%20table" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRzCAK#:~:text=Policy%20based%20forwarding%20allows%20you,to%20tweak%20the%20routing%20table&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I spent countless hours with PA engineers and they confirmed that the setup looks good, but for some reason they couldn't figure out why this setup is not working.&lt;/P&gt;
&lt;P&gt;any thoughts? Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Anees10_0-1666768952880.png" style="width: 781px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44881iFAF597FCD8CB5651/image-dimensions/781x41/is-moderation-mode/true?v=v2" width="781" height="41" role="button" title="Anees10_0-1666768952880.png" alt="Anees10_0-1666768952880.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Anees10_3-1666769066909.png" style="width: 794px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44884iC58728A8FCDFAAAB/image-dimensions/794x66/is-moderation-mode/true?v=v2" width="794" height="66" role="button" title="Anees10_3-1666769066909.png" alt="Anees10_3-1666769066909.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Anees10_5-1666769175304.png" style="width: 887px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44886i9C47E15497C378A3/image-dimensions/887x54/is-moderation-mode/true?v=v2" width="887" height="54" role="button" title="Anees10_5-1666769175304.png" alt="Anees10_5-1666769175304.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Anees10_6-1666769225950.png" style="width: 858px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44887iA3FBF0A53F20B287/image-dimensions/858x172/is-moderation-mode/true?v=v2" width="858" height="172" role="button" title="Anees10_6-1666769225950.png" alt="Anees10_6-1666769225950.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 07:33:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-is-not-working-for-secondary-isp/m-p/519167#M107660</guid>
      <dc:creator>Anees10</dc:creator>
      <dc:date>2022-10-26T07:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding is not working for Secondary ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-is-not-working-for-secondary-isp/m-p/519243#M107667</link>
      <description>&lt;P&gt;Does the traffic from the single server egress out ISP 1 even with the PBF in place?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do the logs show anything interesting with rule hits, allow/deny, etc?&lt;/P&gt;
&lt;P&gt;Any packet captures on any interfaces to track where the traffic is going?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 14:33:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-is-not-working-for-secondary-isp/m-p/519243#M107667</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-10-26T14:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding is not working for Secondary ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-is-not-working-for-secondary-isp/m-p/519244#M107668</link>
      <description>&lt;P&gt;Thanks for your reply.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. The single server doesn't have internet connectivity. It can still talk to the other servers on the LAN but it doesn't have internet connectivity.&lt;/P&gt;
&lt;P&gt;2. Captures show that ARP requests are incomplete. This could be due to the fact that there is no VR configured for ISP2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt;show arp all &lt;BR /&gt;ethernet1/10 147.129.178.129 (incomplete) ethernet1/10 i 1&lt;/P&gt;
&lt;P&gt;&amp;gt;show counter global filter packet-filter yes delta yes severity drop&lt;BR /&gt;flow_fwd_l3_noarp 7 0 drop flow forward Packets dropped: no ARP&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 14:48:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-is-not-working-for-secondary-isp/m-p/519244#M107668</guid>
      <dc:creator>Anees10</dc:creator>
      <dc:date>2022-10-26T14:48:04Z</dc:date>
    </item>
  </channel>
</rss>

