<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does anti-spoofing work when there is no default route configured and when policy based forwarding is enabled in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-anti-spoofing-work-when-there-is-no-default-route/m-p/26247#M19164</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sarish,&lt;/P&gt;&lt;P&gt;The PANFW would still perform route lookup for the traffic coming in from the source zone/ source interface. If the PANFW detects that the traffic ingressing the traffic comes on the incorrect interface, it drops them as spoofed packets or with "no-arp-found" message. It cannot check the same for the destination address because, we are forcing the firewall to route the traffic out via another interface. After the traffic matches a PBF rule, the traffic is subjected to a security rule match, and a session would be setup for the traffic&amp;nbsp; ( client to source and return traffic-source to client). Both the client to server and the server to client traffic is again subjected to other security checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Jul 2013 13:59:11 GMT</pubDate>
    <dc:creator>kprakash</dc:creator>
    <dc:date>2013-07-18T13:59:11Z</dc:date>
    <item>
      <title>How does anti-spoofing work when there is no default route configured and when policy based forwarding is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-anti-spoofing-work-when-there-is-no-default-route/m-p/26246#M19163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise, how does the PANOS handle antispoofing when there is no default route configured in a VR, only the policy based forwarding is enabled within that VR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the policy based forwarding entry update the routing table entries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sarish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 13:47:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-anti-spoofing-work-when-there-is-no-default-route/m-p/26246#M19163</guid>
      <dc:creator>T_SystemsSouthAfrica</dc:creator>
      <dc:date>2013-07-18T13:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: How does anti-spoofing work when there is no default route configured and when policy based forwarding is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-anti-spoofing-work-when-there-is-no-default-route/m-p/26247#M19164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sarish,&lt;/P&gt;&lt;P&gt;The PANFW would still perform route lookup for the traffic coming in from the source zone/ source interface. If the PANFW detects that the traffic ingressing the traffic comes on the incorrect interface, it drops them as spoofed packets or with "no-arp-found" message. It cannot check the same for the destination address because, we are forcing the firewall to route the traffic out via another interface. After the traffic matches a PBF rule, the traffic is subjected to a security rule match, and a session would be setup for the traffic&amp;nbsp; ( client to source and return traffic-source to client). Both the client to server and the server to client traffic is again subjected to other security checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 13:59:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-anti-spoofing-work-when-there-is-no-default-route/m-p/26247#M19164</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-07-18T13:59:11Z</dc:date>
    </item>
  </channel>
</rss>

