<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBF policy not working. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-policy-not-working/m-p/43662#M32039</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no way to specify traffic that came in on Eth1/10 needs to go out on Eth1/10. PBF is based on&amp;nbsp; zones, IPs, App and Service. If the traffic on on Eth1/10 all comes from a small set of networks, you can just add static routes to direct traffic back out the same interface.&lt;/P&gt;&lt;P&gt;PBFis used to defeat or override the routing table. If this is a 2 ISP scenario and traffic that comes in from ISP1 interface should go out the ISP1 interface you might try usng NAT to manipulate the source IP but this gets complicated quickly. You probably need to test this and open a support call if you get stuck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Jun 2011 19:24:37 GMT</pubDate>
    <dc:creator>skrall</dc:creator>
    <dc:date>2011-06-15T19:24:37Z</dc:date>
    <item>
      <title>PBF policy not working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-policy-not-working/m-p/43661#M32038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;I have packets that arrive on interface eth1/10 that I need to be forwarded back out of eth1/10 with a next hop address of another router on that subnet. I have created a pbf rule that I hope would achieve this however it is currently not working. It looks like the following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;==========================================================&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Interface eth1/10 IP : 3.3.3.1&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Interface eth1/10 Zone : dummy-zone1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Source Zone : dummy-zone1&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Source Address : any&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;User : any&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Destination Address : [*NEGATE* : 1.1.1.1] (so I would like the pbr rule to apply to all traffic that does not match the configured address i.e.2.2.2.2)&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Application : any&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Service : any&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Action : forward&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Forwarding Egress I/F : eth1/10&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Next Hop : 3.3.3.2&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;No Monitoring&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;==========================================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Unfortuanly I am not currently familiar enough with PA to run any extensive debugging. Also, is it possible to apply a pbr policy with an egress interface being the same as the source interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;I have substituted the real IP addressing with dummy addressing in the example above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Any comments or suggestions would be appreciated, this is my first post so be gentle &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;Regards,&lt;/P&gt;&lt;P style="margin:0cm;margin-bottom:.0001pt;background:#F8FAFD"&gt;James.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2011 14:52:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-policy-not-working/m-p/43661#M32038</guid>
      <dc:creator>debsPal0</dc:creator>
      <dc:date>2011-06-14T14:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: PBF policy not working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-policy-not-working/m-p/43662#M32039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no way to specify traffic that came in on Eth1/10 needs to go out on Eth1/10. PBF is based on&amp;nbsp; zones, IPs, App and Service. If the traffic on on Eth1/10 all comes from a small set of networks, you can just add static routes to direct traffic back out the same interface.&lt;/P&gt;&lt;P&gt;PBFis used to defeat or override the routing table. If this is a 2 ISP scenario and traffic that comes in from ISP1 interface should go out the ISP1 interface you might try usng NAT to manipulate the source IP but this gets complicated quickly. You probably need to test this and open a support call if you get stuck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 19:24:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-policy-not-working/m-p/43662#M32039</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-06-15T19:24:37Z</dc:date>
    </item>
  </channel>
</rss>

