<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Based Forwading Capability Question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67679#M39634</link>
    <description>&lt;P&gt;So the PAN interface doesnt need to be on the same vlan segment, it should just need to have the traffic routed to it. The PBF then should be setup by source and then flow out a destination interface on the PAN. The interface shouldnt need to be on the same segment as long as the way the packets flow out they get sent towards their intended destination.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I dont think I did a good job explaining this. Here is the link to a PBF doc that does a good job explaing it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Policy-Based-Forwarding/ta-p/54408" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Policy-Based-Forwarding/ta-p/54408&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Nov 2015 00:07:13 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2015-11-05T00:07:13Z</dc:date>
    <item>
      <title>Policy Based Forwading Capability Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67662#M39628</link>
      <description>&lt;P&gt;Hello All, Was just wondering if anyone may be able to help with this our question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see the attached High Level Diagram. Both Firewalls are PA 3020's with the full licence set enabled. We need to replace the ISA server which is not providing any other functions than forwarding the traffic down one of the 3 paths in the diagram, unfortunately we need to maintain this capability owing to some historic complexities with certain applications in our infrastructure not working through our proxy or via the cloud proxy or vice versa.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG title="Data Flows.jpg" alt="Data Flows.jpg" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1062i5BED10BAE6440948/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;I know the PA can do Policy based forwarding which would suffice for the passage of traffic either via the Local Proxy or directly out via the ISP router. Everything I have read would suggest that the PBF is more of a routing level thing which requires an interface in the same subnet within the PA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Obviously this is not possible for the cloud hosted proxy, if we were to set the egress interface and just put the next hop address as the cloud proxy would that function. My inclination is that the next hop needs to be exactly that but just looking for confirmation before I buy another solution. Thanks in Advance&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 16:03:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67662#M39628</guid>
      <dc:creator>WesNeary</dc:creator>
      <dc:date>2015-11-04T16:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwading Capability Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67679#M39634</link>
      <description>&lt;P&gt;So the PAN interface doesnt need to be on the same vlan segment, it should just need to have the traffic routed to it. The PBF then should be setup by source and then flow out a destination interface on the PAN. The interface shouldnt need to be on the same segment as long as the way the packets flow out they get sent towards their intended destination.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I dont think I did a good job explaining this. Here is the link to a PBF doc that does a good job explaing it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Policy-Based-Forwarding/ta-p/54408" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Policy-Based-Forwarding/ta-p/54408&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 00:07:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67679#M39634</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-05T00:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwading Capability Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67684#M39637</link>
      <description>&lt;P&gt;Hi Otakar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the reply, i think i may not have explained this fully, we are trying to replace the ISA server whihc at the moment based on policy directs the traffic to the cloud proxy by ammending the packet header and its this function i am wondering whether the PA can reproduce to allow us to remove the ISA.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 07:41:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67684#M39637</guid>
      <dc:creator>WesNeary</dc:creator>
      <dc:date>2015-11-05T07:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwading Capability Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67712#M39652</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I think the answer here is it depends on what the ISA server is currently doing to detect/authorize traffic. The PAN can do somethings but not everything. It would be helpful if you could explain, without give us the keys to the kingdom, what actions/inspections the ISA server is currently performing. I think based on that we could determine if the PAN can replace the ISA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 18:33:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67712#M39652</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-05T18:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwading Capability Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67920#M39727</link>
      <description>&lt;P&gt;Hi WesNeary...Are your users explicitly proxied (browser set to use proxy server) to the ISA server, and the ISA server is using proxy chaining to connect the cloud service? &amp;nbsp;In other words, the ISA server is configured to use an upstream proxy server = cloud service.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 20:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67920#M39727</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2015-11-10T20:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwading Capability Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67999#M39765</link>
      <description>&lt;P&gt;Hi Rmonvon&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct clients have the ISA set as there browser proxy this then based on its rulesets forwards the traffic to either our onsite proxy, the upstream proxy or directly to the internet.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 09:58:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwading-capability-question/m-p/67999#M39765</guid>
      <dc:creator>WesNeary</dc:creator>
      <dc:date>2015-11-12T09:58:13Z</dc:date>
    </item>
  </channel>
</rss>

