<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy forwarding question. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-forwarding-question/m-p/24976#M18219</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I figured what I was doing wrong.&amp;nbsp; I think the policy was matching on return from the packet shaper and being sent through it again until TTL expired.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 Apr 2013 14:38:13 GMT</pubDate>
    <dc:creator>roadracer96</dc:creator>
    <dc:date>2013-04-01T14:38:13Z</dc:date>
    <item>
      <title>Policy forwarding question.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-forwarding-question/m-p/24975#M18218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;An over-simplified explanation of my setup.&amp;nbsp; Trust me, it just has to be this way.&amp;nbsp; &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ethernet1/1 - Internet 1.2.3.1/24&lt;/P&gt;&lt;P&gt;ethernet1/2 - LAN 10.10.10.1/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nat/dnat/1-1 nat between ethernet 1/1 and 1/2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a traffic shaping appliance that I need to loop data through BEFORE NAT on the palo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trust me when I say I just cant stick it between the lan and palo.&amp;nbsp; In a nutshell, I have multiple virtual systems that all need to be looped through the shaper in a complex network.&amp;nbsp; Only data destined for the internet should go through the traffic shaper.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I WANT to do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ethernet1/1 - Internet 1.2.3.1/24&lt;/P&gt;&lt;P&gt;ethernet1/2 - LAN 10.10.10.1/24&lt;/P&gt;&lt;P&gt;ethernet1/3 - 10.0.0.1/30 Shaper Internal side, in LAN zone&lt;/P&gt;&lt;P&gt;ethernet1/4 - 10.0.0.2/30 Shaper External side in LAN zone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The shaper is transparent.&amp;nbsp; It would be the same as ethernet1/3 and 1/4 being patched together.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Policy forwarding.&lt;/P&gt;&lt;P&gt;Anything outbound to internet from lan zone, next hop 10.0.0.2 egress interface ethernet 1/3&lt;/P&gt;&lt;P&gt;Anything coming in from internet zone to lan, next hop 10.0.0.1 egress interface ethernet 1/4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried this once with to virtual routers in the vsys and routing between them.&amp;nbsp; It didnt work as I expected.&amp;nbsp; I stopped there and figured I would ask if im barking up the wrong tree and it just isnt going to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Input welcome!&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Apr 2013 12:56:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-forwarding-question/m-p/24975#M18218</guid>
      <dc:creator>roadracer96</dc:creator>
      <dc:date>2013-04-01T12:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Policy forwarding question.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-forwarding-question/m-p/24976#M18219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I figured what I was doing wrong.&amp;nbsp; I think the policy was matching on return from the packet shaper and being sent through it again until TTL expired.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Apr 2013 14:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-forwarding-question/m-p/24976#M18219</guid>
      <dc:creator>roadracer96</dc:creator>
      <dc:date>2013-04-01T14:38:13Z</dc:date>
    </item>
  </channel>
</rss>

