<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can you set policy based forwarding in a virtual wire deployment? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22133#M16129</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally, when traffic enters the firewall, the ingress interface virtual router dictates the route that &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;determines&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; the outgoing interface and destination security zone based on destination IP address. With &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;policy&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;-based forwarding (PBF), you can specify other information to determine the outgoing interface, &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;including&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; source and destination IP addresses, source and destination ports, and user ID.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;But, in your case, once you will deploy virtual wire into PA firewall, there are no more routing involves into it. In virtual mode PA firewall acts as a "transparent device" and can not implement PBF into it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct"&gt;Subhankar&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 21 Jul 2013 02:17:51 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2013-07-21T02:17:51Z</dc:date>
    <item>
      <title>Can you set policy based forwarding in a virtual wire deployment?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22131#M16127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have our PA firewall set in virtual wire deployment. Can i set PBF's so I can do things like route things like audio-streaming to a cable modem that we have attached to the firewall? I've tried and when trying to set the zone/interface it doesn't list the vwire interfaces as options. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Jul 2013 21:43:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22131#M16127</guid>
      <dc:creator>Netwerx</dc:creator>
      <dc:date>2013-07-20T21:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can you set policy based forwarding in a virtual wire deployment?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22132#M16128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PBF is source based routing where the traditional routing is destination based. When routing is involved and you need Layer 3 interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot deploy pbf in v-wire. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Jul 2013 22:41:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22132#M16128</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2013-07-20T22:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Can you set policy based forwarding in a virtual wire deployment?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22133#M16129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally, when traffic enters the firewall, the ingress interface virtual router dictates the route that &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;determines&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; the outgoing interface and destination security zone based on destination IP address. With &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;policy&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;-based forwarding (PBF), you can specify other information to determine the outgoing interface, &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;including&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; source and destination IP addresses, source and destination ports, and user ID.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;But, in your case, once you will deploy virtual wire into PA firewall, there are no more routing involves into it. In virtual mode PA firewall acts as a "transparent device" and can not implement PBF into it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct"&gt;Subhankar&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Jul 2013 02:17:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22133#M16129</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-07-21T02:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can you set policy based forwarding in a virtual wire deployment?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22134#M16130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, so I need to set two other interfaces as layer 3, probably to the default virtual router. For that I'll need to assign two IP addresses to it, one for each interface. Will this interfere with normal traffic going to the default gateway router? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Jul 2013 19:50:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22134#M16130</guid>
      <dc:creator>Netwerx</dc:creator>
      <dc:date>2013-07-21T19:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can you set policy based forwarding in a virtual wire deployment?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22135#M16131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you are right. Please follow below mentioned documents for more in details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;A class="jive-link-wiki-small" data-containerid="2021" data-containertype="14" data-objectid="3220" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3220"&gt;https://live.paloaltonetworks.com/docs/DOC-3220&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Subhankar&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 00:18:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-set-policy-based-forwarding-in-a-virtual-wire-deployment/m-p/22135#M16131</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-07-22T00:18:18Z</dc:date>
    </item>
  </channel>
</rss>

