<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone to zone interaction  PBF in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-interaction-pbf/m-p/583004#M116557</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dia" style="width: 956px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58898i4DC695A5B91BF3C6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="net.JPG" alt="dia" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;dia&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2024 06:10:43 GMT</pubDate>
    <dc:creator>pyrainath</dc:creator>
    <dc:date>2024-04-09T06:10:43Z</dc:date>
    <item>
      <title>Zone to zone interaction  PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-interaction-pbf/m-p/583001#M116556</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;i have some doubts ....&lt;/P&gt;
&lt;P&gt;1.i have three zone TRUST,DMZ,UNTRUST.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.there is a nat policy from TRUST zone, DMZ zone to untrust&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.all interface is under same VR .and there i haven't add any static route yet. instead i create a PBF rule from both TRUST AND DMZ to UNTRUST (destination interface=untrust interface, next-hop untrust pc)&lt;/P&gt;
&lt;P&gt;4.Securty policy to allow traffic from trust,DMZ to untrust zone&lt;/P&gt;
&lt;P&gt;5.i can reach to untrust PC from DMZ,TRUST&amp;nbsp; .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want my trust and dmz to communicate each other so i simply add the security rule which allow traffic from trust to dmz,dmz to trust.&lt;/P&gt;
&lt;P&gt;but nothing worked as i expected. when i checked the traffic i saw that the traffic from trust is getting nated to the untrust ip and the traffic flow showing that it is going from trust to untrust . same goes for when i tried ping to trust from dmz zone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so i disabled the pbf rule and every things working . whenever i enable the pbf rule its getting nated to untrust interface ip also its working when i create a static route for interacting with untrust.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;only thing is these zones cant communicate each other if i enabled the PBF.any idea why this is happening&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 06:04:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-interaction-pbf/m-p/583001#M116556</guid>
      <dc:creator>pyrainath</dc:creator>
      <dc:date>2024-04-09T06:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Zone to zone interaction  PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-interaction-pbf/m-p/583004#M116557</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dia" style="width: 956px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58898i4DC695A5B91BF3C6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="net.JPG" alt="dia" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;dia&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 06:10:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-interaction-pbf/m-p/583004#M116557</guid>
      <dc:creator>pyrainath</dc:creator>
      <dc:date>2024-04-09T06:10:43Z</dc:date>
    </item>
  </channel>
</rss>

