<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help setting up a return route in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30325#M22173</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am in the process of migrating internet connections, at the moment we have a PA-500 with 3 active internet connections, traffic is routed between different connections using policy routing. This is fine for outbound traffic, however inbound does not work as the traffic attempts to return via the default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There seems to be no implementation of Reverse Path Forwarding (RPF) to return the traffic for the origin interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to know if there is a way to set this up. The problem at hand is our mail and webmail is coming in on the "eth0/1" interface which will soon be decommisioned, however during the interum (DNS propergation) we need to have both eth0/1 and eth0/3 accepting traffic for https, smtp, and smtps simaltaniously with the default route going via eth0/3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attempted to try and return the traffic via PBF with no success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goal is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default Route - eth0/3&lt;/P&gt;&lt;P&gt;Incoming traffic on eth0/1 goes to internal network, then returns via eth0/1, NOT eth0/3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help before I loose all my hair &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dean.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Mar 2011 06:55:39 GMT</pubDate>
    <dc:creator>andyyps</dc:creator>
    <dc:date>2011-03-09T06:55:39Z</dc:date>
    <item>
      <title>Help setting up a return route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30325#M22173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am in the process of migrating internet connections, at the moment we have a PA-500 with 3 active internet connections, traffic is routed between different connections using policy routing. This is fine for outbound traffic, however inbound does not work as the traffic attempts to return via the default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There seems to be no implementation of Reverse Path Forwarding (RPF) to return the traffic for the origin interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to know if there is a way to set this up. The problem at hand is our mail and webmail is coming in on the "eth0/1" interface which will soon be decommisioned, however during the interum (DNS propergation) we need to have both eth0/1 and eth0/3 accepting traffic for https, smtp, and smtps simaltaniously with the default route going via eth0/3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attempted to try and return the traffic via PBF with no success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goal is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default Route - eth0/3&lt;/P&gt;&lt;P&gt;Incoming traffic on eth0/1 goes to internal network, then returns via eth0/1, NOT eth0/3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help before I loose all my hair &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dean.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2011 06:55:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30325#M22173</guid>
      <dc:creator>andyyps</dc:creator>
      <dc:date>2011-03-09T06:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Help setting up a return route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30326#M22174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Source nat traffic coming in via eth0/1, that way it will be routed back to the correct interface. That is at least one way of solving it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2011 07:39:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30326#M22174</guid>
      <dc:creator>rapoint_person</dc:creator>
      <dc:date>2011-03-09T07:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Help setting up a return route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30327#M22175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you give me an example of how I would do this? I have configured "dynamic ip and port" to the next hop with no dice.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 00:05:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30327#M22175</guid>
      <dc:creator>andyyps</dc:creator>
      <dc:date>2011-03-10T00:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Help setting up a return route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30328#M22176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My idea was this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Source NAT (And destination nat) traffic coming in on ethernet0/1. Let's say:&lt;/P&gt;&lt;P&gt;Original SRC packet: 195.1.1.1&lt;/P&gt;&lt;P&gt;Original DST packet: 210.1.1.1&lt;/P&gt;&lt;P&gt;NAT SRC packet: 192.168.1.1&lt;/P&gt;&lt;P&gt;NAT DST packet:10.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Keep your default route pointing to ethernet0/3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The idea beeing the 192.168.1.1 source address will be the new source of the packet and should be routed back to the correct interface (ethernet0/1) simply because it is a connected route. No need for PBF for this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have never tried this in a Palo box (but a similar config in a Juniper/Netscreen worked).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it works!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 18:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30328#M22176</guid>
      <dc:creator>rapoint_person</dc:creator>
      <dc:date>2011-03-10T18:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Help setting up a return route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30329#M22177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have solved this problem? I have a similar situation in PAN 4.0.1. Why PAN don't have RPF for NAT traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Apr 2011 09:00:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30329#M22177</guid>
      <dc:creator>commcord</dc:creator>
      <dc:date>2011-04-03T09:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Help setting up a return route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30330#M22178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly the same problem here.&lt;/P&gt;&lt;P&gt;Does anyone know if there is way around it using Source NAT rules? I've tried, but no luck so far...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 15:01:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-setting-up-a-return-route/m-p/30330#M22178</guid>
      <dc:creator>slawek.kunach</dc:creator>
      <dc:date>2011-07-15T15:01:45Z</dc:date>
    </item>
  </channel>
</rss>

