<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Policy Based Forwarding only works when using specific IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-only-works-when-using-specific-ip/m-p/31576#M23086</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thinking outloud here...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to record voice traffic for VPN connected customer service agents.&lt;/P&gt;&lt;P&gt;Traffic comes in a VPN-HomeRouters tunnel from a 10. IP range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PBF works when setting source Zone and IP, Next Hop and 1 destination IP.&lt;/P&gt;&lt;P&gt;When i change the IP to a range then the forwarding gets skipped (i'm thinking because of the Virtual Router static route)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i'm wondering if skipping the PBF altogether in a favor of a second Virtual router will do the trick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second VR would include the tunnel interface and e1/5 (my desired egress interface into the LAN) and have static routes matching that of the Main VR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bottom line I need VPN traffic to egress e1/5 in order to hit a spanned port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any voices in my head would be most welcome!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gary &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Nov 2012 22:11:05 GMT</pubDate>
    <dc:creator>startech_netadmins</dc:creator>
    <dc:date>2012-11-23T22:11:05Z</dc:date>
    <item>
      <title>Policy Based Forwarding only works when using specific IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-only-works-when-using-specific-ip/m-p/31576#M23086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thinking outloud here...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to record voice traffic for VPN connected customer service agents.&lt;/P&gt;&lt;P&gt;Traffic comes in a VPN-HomeRouters tunnel from a 10. IP range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PBF works when setting source Zone and IP, Next Hop and 1 destination IP.&lt;/P&gt;&lt;P&gt;When i change the IP to a range then the forwarding gets skipped (i'm thinking because of the Virtual Router static route)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i'm wondering if skipping the PBF altogether in a favor of a second Virtual router will do the trick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second VR would include the tunnel interface and e1/5 (my desired egress interface into the LAN) and have static routes matching that of the Main VR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bottom line I need VPN traffic to egress e1/5 in order to hit a spanned port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any voices in my head would be most welcome!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gary &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2012 22:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-only-works-when-using-specific-ip/m-p/31576#M23086</guid>
      <dc:creator>startech_netadmins</dc:creator>
      <dc:date>2012-11-23T22:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding only works when using specific IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-only-works-when-using-specific-ip/m-p/31577#M23087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gary,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I couldn't understand the exact scenario ;however I would like to mention few points...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- PBF would work well for a single destination IP,Group of IPs or a subnet&lt;/P&gt;&lt;P&gt;- PBF got priority over the VR static routes (if it is applicable to source and destination zones)and PBF works from top to bottom.Please check&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; if you have any PBF on the top&amp;nbsp; that overwirtes&amp;nbsp;&amp;nbsp;&amp;nbsp; your PBF&lt;/P&gt;&lt;P&gt;- If you dont have an IP for tunnel interface and if you are trying to do a PBF with next hop as the tunnel interface,the forwarding decicion&lt;/P&gt;&lt;P&gt;&amp;nbsp; wouldn't work . You should have tunnel interface with an IP address to make forwarding decision with PBF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Else what you can do is -make tunnel interface unnumbered ,then make PBF as no forwarding and then add a static route in the VR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps ... &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,Nikhil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 08:54:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-only-works-when-using-specific-ip/m-p/31577#M23087</guid>
      <dc:creator>BFCBahrain</dc:creator>
      <dc:date>2012-12-13T08:54:21Z</dc:date>
    </item>
  </channel>
</rss>

