<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarding with pbf No Nat in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49076#M36152</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on your policy it looks like you are accessing a private ip (dmz) using oublic ip address.&lt;/P&gt;&lt;P&gt;correct me if I am wrong.&lt;/P&gt;&lt;P&gt;In that situation you need nat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Dec 2013 12:22:35 GMT</pubDate>
    <dc:creator>hyadavalli</dc:creator>
    <dc:date>2013-12-10T12:22:35Z</dc:date>
    <item>
      <title>forwarding with pbf No Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49073#M36149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We wanted to forward the traffic coming on public interface (1.1.1.1) with port 80 to an another ip address on another interface (DMZ - 2.2.2.2)&lt;/P&gt;&lt;P&gt;just to forward, not want to NAT,&lt;/P&gt;&lt;P&gt;we've written a Pbf untrust to 1.1.1.1 with destination port 80 forward eth/DMZ 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That did not work.Also traffic doesn't match to that pbf.What is missing ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Dec 2013 21:41:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49073#M36149</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-12-09T21:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding with pbf No Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49074#M36150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you post the output of 'show running pbf-policy' or a screen shot of your configuration, to verify that the config is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;tasonibare&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 01:25:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49074#M36150</guid>
      <dc:creator>tasonibare</dc:creator>
      <dc:date>2013-12-10T01:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding with pbf No Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49075#M36151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;test {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; id 5;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; from WAN3;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination 8X.10X.10.7X;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; user any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; application/service&amp;nbsp; any/tcp/any/23;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; action Forward;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; symmetric-return no;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; forwarding-egress-IF/VSYS ethernet1/11;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; next-hop 10.10.0.48;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; terminal no;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 06:50:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49075#M36151</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-12-10T06:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding with pbf No Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49076#M36152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on your policy it looks like you are accessing a private ip (dmz) using oublic ip address.&lt;/P&gt;&lt;P&gt;correct me if I am wrong.&lt;/P&gt;&lt;P&gt;In that situation you need nat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 12:22:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49076#M36152</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2013-12-10T12:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding with pbf No Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49077#M36153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can forward a public ip to a private ip.I just wanted to tell pbf is not working.when I hit used rules it comes with colour.session is not matching to pbf.&lt;/P&gt;&lt;P&gt;flow logic, pbf is first.Nat is later.We also have a destination Nat rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 12:31:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49077#M36153</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-12-10T12:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding with pbf No Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49078#M36154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your understanding is correct; pbf should come before NAT and it should supersede traditional routing as well.&lt;/P&gt;&lt;P&gt;If your traffic is coming in on zone/interface WAN3 and destined to the destination IP you have configured, and the firewall is not forwarding the packets to eth1/11, then I'll suggest you open a ticket to have this looked into.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can verify the ingress and egress interfaces/zones of the packet by running 'show session id #' in CLI as well. It is possible that the ingress of the packet is not matching your configured PBF policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;tasonibare&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 18:27:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49078#M36154</guid>
      <dc:creator>tasonibare</dc:creator>
      <dc:date>2013-12-10T18:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding with pbf No Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49079#M36155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can also test your pbf rule by using the test command on the CLI:&lt;/P&gt;&lt;P&gt;admin@PA&amp;gt; test pbf-policy-match&lt;/P&gt;&lt;P&gt;+ application&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application name&lt;/P&gt;&lt;P&gt;+ destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination IP address&lt;/P&gt;&lt;P&gt;+ destination-port&amp;nbsp;&amp;nbsp; Destination port&lt;/P&gt;&lt;P&gt;+ from&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; From zone&lt;/P&gt;&lt;P&gt;+ from-interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; From interface&lt;/P&gt;&lt;P&gt;+ ha-device-id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HA Active-Active device ID&lt;/P&gt;&lt;P&gt;+ protocol&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP protocol value&lt;/P&gt;&lt;P&gt;+ source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source IP address&lt;/P&gt;&lt;P&gt;+ source-user&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source User&lt;/P&gt;&lt;P&gt;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Pipe through a command&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;Enter&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Finish input&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Dec 2013 08:09:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-with-pbf-no-nat/m-p/49079#M36155</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2013-12-11T08:09:51Z</dc:date>
    </item>
  </channel>
</rss>

