<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how can i create a PBF rule to send traffic to a http/https proxy? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-create-a-pbf-rule-to-send-traffic-to-a-http-https/m-p/559236#M113420</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216380"&gt;@ptingalls&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, the proxy has to be on the same subnet as the interface.&amp;nbsp; The NGFW will not change the IP header of the original packet.&amp;nbsp; So, it cannot be routed over the network.&amp;nbsp; It must be forwarded to the proxy MAC address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One way to get around that limitation is with a GRE tunnel if the web proxy supports it.&amp;nbsp; Here is a doc for PBF with GRE for Netskope.&amp;nbsp; &lt;A href="https://docs.netskope.com/en/netskope-help/integrations-439794/ipsec-and-gre/netskope-gre-with-palo-alto-networks-ngfw/palo-alto-networks-ngfw-configuration/" target="_blank"&gt;https://docs.netskope.com/en/netskope-help/integrations-439794/ipsec-and-gre/netskope-gre-with-palo-alto-networks-ngfw/palo-alto-networks-ngfw-configuration/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the web proxy does not support GRE, then you will need to extend the VLAN to the NGFW.&amp;nbsp; I could be wrong, but I think those are your only 2 options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Sun, 24 Sep 2023 01:09:03 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-09-24T01:09:03Z</dc:date>
    <item>
      <title>how can i create a PBF rule to send traffic to a http/https proxy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-create-a-pbf-rule-to-send-traffic-to-a-http-https/m-p/559235#M113419</link>
      <description>&lt;P&gt;when i'm trying to set up the rule, where the next hop is the IP of the proxy - i get an error that this IP "does not match subnets defined on the PBF interface" - which is correct, it's on different subnet. What are my options? Do i have to have the proxy on the same subnet as the interface?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2023 18:36:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-create-a-pbf-rule-to-send-traffic-to-a-http-https/m-p/559235#M113419</guid>
      <dc:creator>ptingalls</dc:creator>
      <dc:date>2023-09-23T18:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: how can i create a PBF rule to send traffic to a http/https proxy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-create-a-pbf-rule-to-send-traffic-to-a-http-https/m-p/559236#M113420</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216380"&gt;@ptingalls&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, the proxy has to be on the same subnet as the interface.&amp;nbsp; The NGFW will not change the IP header of the original packet.&amp;nbsp; So, it cannot be routed over the network.&amp;nbsp; It must be forwarded to the proxy MAC address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One way to get around that limitation is with a GRE tunnel if the web proxy supports it.&amp;nbsp; Here is a doc for PBF with GRE for Netskope.&amp;nbsp; &lt;A href="https://docs.netskope.com/en/netskope-help/integrations-439794/ipsec-and-gre/netskope-gre-with-palo-alto-networks-ngfw/palo-alto-networks-ngfw-configuration/" target="_blank"&gt;https://docs.netskope.com/en/netskope-help/integrations-439794/ipsec-and-gre/netskope-gre-with-palo-alto-networks-ngfw/palo-alto-networks-ngfw-configuration/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the web proxy does not support GRE, then you will need to extend the VLAN to the NGFW.&amp;nbsp; I could be wrong, but I think those are your only 2 options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2023 01:09:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-create-a-pbf-rule-to-send-traffic-to-a-http-https/m-p/559236#M113420</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-24T01:09:03Z</dc:date>
    </item>
  </channel>
</rss>

