<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Skype and PBF in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44137#M32405</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was about to ask the same question...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reasons I can see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Efficient way to find out who is actually reading the manual(s) and who doesnt? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) For non-NAT situations (for example if you have Internetrouter &amp;lt;-&amp;gt; PA &amp;lt;-&amp;gt; ISP) you can use the PA device to let specific application traffic use a dedicated interface either for performance reasons or for capture reasons (send a specific application through a dedicated interface where you have a switch with span enabled to record the application(s) you are interrested of).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The performance reason could also have to do with QoS - its easier for your router to statically prioritze incoming traffic at a specific interface instead of having the router try to find out what is youtube (as example) and what isnt. This way your internetrouter could (for example) put youtube traffic on a lower QoS priority where the PA is the device to identify what should go for int 0/1 and what should go out at int 0/2 (without having to enable QoS in PA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it would be bad if this option is removed, however it should possibly be a better warning in the GUI that "are you really sure you know what you are doing? see section x.x in admin gui for more info why we bugger you with this red text" or something shorter...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 22 Apr 2012 01:30:12 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-04-22T01:30:12Z</dc:date>
    <item>
      <title>Skype and PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44131#M32399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two ISP's connected to our PA FW (4.1.5). ISP A (e1/5) is the default for all outbound internet traffic. ISP B (e1/7) is the backup link. Now we would like to use the backup link for all skype related traffic. Until now I did not have success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created the follwoing PBF rule:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PBF-Rule.jpg" class="jive-image-thumbnail jive-image" onclick="" src="https://live.paloaltonetworks.com/legacyfs/online/2863_PBF-Rule.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But skype still gets forwarded to ISP A. Is there anything missing ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TNX Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2012 13:06:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44131#M32399</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2012-04-20T13:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Skype and PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44132#M32400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Roland,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is the PBF working correctly at all with the 4.1.5 in your setup?&lt;/P&gt;&lt;P&gt;I'm asking because we are running the 4.1.5 too.&lt;/P&gt;&lt;P&gt;And we have the "funny" issue that the traffic is routed to both interfaces to the pbf created gateway &lt;STRONG&gt;and&lt;/STRONG&gt; the default gw.&lt;/P&gt;&lt;P&gt;This leads to very slow connections and of course connections with to different public IP-addresses. (the ip via pbf = tcp_established and the via default gw = tcp_syn)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We already opened a case but PAN will not look at our system until Monday.&lt;/P&gt;&lt;P&gt;But I believe it's a bug in 4.1.5&lt;/P&gt;&lt;P&gt;Maybe you can check that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2012 13:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44132#M32400</guid>
      <dc:creator>sebastian</dc:creator>
      <dc:date>2012-04-20T13:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Skype and PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44133#M32401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sebastian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good point. I have gone through some further testing. I tried the same for app web-browsing and it worked at least a sort of... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is my PBF rule for web-browsing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PBF.jpg" class="jive-image-thumbnail jive-image" onclick="" src="https://live.paloaltonetworks.com/legacyfs/online/2864_PBF.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And this is what I see in the traffic log for web-traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PBF-log.jpg" class="jive-image-thumbnail jive-image" onclick="" src="https://live.paloaltonetworks.com/legacyfs/online/2865_PBF-log.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you see not all the web-browsing traffic is leaving the correct interface according the PBF rule....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is confusing me even more. I tried to use the easiest case with the app web-browsing, it has no dependencies and schould be fairly easy to identify from an APP-ID perspective.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe indeed a bug ? Who knows ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2012 14:42:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44133#M32401</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2012-04-20T14:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: Skype and PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44134#M32402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I have understood previous info regarding PBF correctly using application for PBF is not recommended by the manual.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is because the initial syn/synack/ack will go out through whatever your VROUTER tells it to use (your regular defgw, lets say ISP-A).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not until the flow is recognized as web-browsing (or whatever) it will use ISP-B as nexthop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem here comes if you use SNAT at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means that the webserver first receives a syn/synack/ack from ISP-A ip and then suddently regular packets through ISP-B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will of course (in most cases) fail at the server side since the stuff from ISP-B didnt handshake properly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2012 21:36:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44134#M32402</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-04-20T21:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: Skype and PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44135#M32403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a snippet from the admin guide on using apps with PBF:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"The initial session on a given destination IP address and port that is associated with an application will not match an application-specific rule and will be forwarded according to subsequentPBF rules (that do not specify an application) or the virtual router’s forwarding table. Allsubsequent sessions on that destination IP address and port for the same application willmatch an application-specific rule. To ensure forwarding through PBF rules, application specific rules are not recommended."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which means the PBF rule will not match 100% of the time. PBF routing is determined by the first packet and most of the apps we have are not identified with the first packet which implies this will take the normal routing route. After the app is identified, the subsequent sessions of the same app with same src and destn will match the PBF rule. Again, it is not recommended to use apps with PBF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2012 21:54:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44135#M32403</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-04-20T21:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Skype and PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44136#M32404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay since it is not recommended to use apps in PBF and not working reliably why is it a configurable option ?&lt;/P&gt;&lt;P&gt;Other than creating FUD and support calls I don't see any benefit ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Apr 2012 09:33:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44136#M32404</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2012-04-21T09:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Skype and PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44137#M32405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was about to ask the same question...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reasons I can see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Efficient way to find out who is actually reading the manual(s) and who doesnt? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) For non-NAT situations (for example if you have Internetrouter &amp;lt;-&amp;gt; PA &amp;lt;-&amp;gt; ISP) you can use the PA device to let specific application traffic use a dedicated interface either for performance reasons or for capture reasons (send a specific application through a dedicated interface where you have a switch with span enabled to record the application(s) you are interrested of).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The performance reason could also have to do with QoS - its easier for your router to statically prioritze incoming traffic at a specific interface instead of having the router try to find out what is youtube (as example) and what isnt. This way your internetrouter could (for example) put youtube traffic on a lower QoS priority where the PA is the device to identify what should go for int 0/1 and what should go out at int 0/2 (without having to enable QoS in PA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it would be bad if this option is removed, however it should possibly be a better warning in the GUI that "are you really sure you know what you are doing? see section x.x in admin gui for more info why we bugger you with this red text" or something shorter...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Apr 2012 01:30:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-and-pbf/m-p/44137#M32405</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-04-22T01:30:12Z</dc:date>
    </item>
  </channel>
</rss>

