<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manual failback for PBF in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74898#M41816</link>
    <description>&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3121iFE34964B2FEDFE75/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="pbf.PNG" title="pbf.PNG" /&gt;On the Policy Based Forwarding rule there is checkbox "Disable this rule if next hop is unreachable"&lt;/P&gt;
&lt;P&gt;Try if this fullfills your requirements.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Mar 2016 19:45:25 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2016-03-17T19:45:25Z</dc:date>
    <item>
      <title>Manual failback for PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74889#M41812</link>
      <description>&lt;P&gt;Is there a way to force PBF rules to have to be manually failved back? As it is now, if our primary ISP fails, we failover to a secondary ISP using PBF. However, once the primary is back up, things fail back to it immediately. We would like to prevent the immediate fail back and not use a timer. ISP recoveries often times flap for a period of time, so we just want to wait it out until the failed ISP is deemed stable and manually fail back. Ideas? Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 16:45:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74889#M41812</guid>
      <dc:creator>cburke</dc:creator>
      <dc:date>2016-03-17T16:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Manual failback for PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74891#M41813</link>
      <description>&lt;P&gt;Hi...When there is a failover to the backup link, you can manually change the PBF rule so it does not fail back to the main link until you're ready. &amp;nbsp;There will be 2 manual steps but you'll get to control when the fail back occur. &amp;nbsp;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 18:02:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74891#M41813</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-03-17T18:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: Manual failback for PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74897#M41815</link>
      <description>&lt;P&gt;So how does one configure such a thing?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 19:32:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74897#M41815</guid>
      <dc:creator>cburke</dc:creator>
      <dc:date>2016-03-17T19:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: Manual failback for PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74898#M41816</link>
      <description>&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3121iFE34964B2FEDFE75/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="pbf.PNG" title="pbf.PNG" /&gt;On the Policy Based Forwarding rule there is checkbox "Disable this rule if next hop is unreachable"&lt;/P&gt;
&lt;P&gt;Try if this fullfills your requirements.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 19:45:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74898#M41816</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-03-17T19:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Manual failback for PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74901#M41818</link>
      <description>&lt;P&gt;Yes, use the 'disable this rule' option as suggested by Raido. &amp;nbsp;Create 2 PBF rules&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;rule1 - send all traffic to primary link with&amp;nbsp;&lt;SPAN&gt;'disable this rule' option &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;rule2 -&amp;nbsp;&lt;SPAN&gt;send all traffic to backup link&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;when primary is down &amp;amp; backup link is active, you need to login and manually disable rule1 to ensure primary is not use until you're ready. &amp;nbsp;When ready, enable rule1 for fail back to occur.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 19:53:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74901#M41818</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-03-17T19:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Manual failback for PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74902#M41819</link>
      <description>&lt;P&gt;Seemingly not. That was the first thing I tried. On my primary ISP I ping 2 separate external polling IPs. If both external polling IPs fail pings (both rules have "Disable this rule if next hop is unreachable"&amp;nbsp;checked), the firewall fails over to the other ISP as expected. This all works perfectly. However, as soon as either external IP comes back up, it fails back automatically. We want to prevent the fail back behavior. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 19:54:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74902#M41819</guid>
      <dc:creator>cburke</dc:creator>
      <dc:date>2016-03-17T19:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Manual failback for PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74904#M41820</link>
      <description>&lt;P&gt;it fails back because that's by design. &amp;nbsp;Hence, I am suggesting that you manually disable the PBF rule such that it does not fail back and manually enable the rule when ready.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 21:14:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74904#M41820</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-03-17T21:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Manual failback for PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74912#M41825</link>
      <description>&lt;P&gt;It's not elegant, but it's possible. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll have to loop-in an external system in order to accomplish this... for example, you could have the firewall syslog the system events to an external server. &amp;nbsp;That server could parse the logs looking for the pbf nh-down events like these:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3122i67B9213F8783BB75/image-size/large?v=mpbl-1&amp;amp;px=-1" border="0" alt="Capture.PNG" title="Capture.PNG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When the next-hop monitor fails and the PBF rule is bypassed, that server can use an API call to take some sort of action, such as:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- disable failed PBF rule, commit... or&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- modify object group membership used in&amp;nbsp;PBF rule, commit... or&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- modify dynamic object group membership used to match PBF rule (no commit required!)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- etc. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 00:42:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74912#M41825</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2016-03-18T00:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Manual failback for PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74914#M41827</link>
      <description>&lt;P&gt;I agree with the suggestions made. There is no way to keep the PBF rules for primary ISP disabled for some time. There has to be some manual intervention or external intervention.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But there should not be any issues with the existing sessions I believe if "&lt;SPAN class="tx"&gt;wait&lt;/SPAN&gt;&lt;SPAN class="tx"&gt;-&lt;/SPAN&gt;&lt;SPAN class="tx"&gt;recover&lt;/SPAN&gt;" is used in the monitoring profile. Is there a problem if new sessions start using primary ISP?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 02:25:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/74914#M41827</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2016-03-18T02:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Manual failback for PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/75007#M41856</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Ok, that makes more sense. So, really more of a procedure than something we can configure. The API call outs are interesting and what we were hoping to avoid, but this is super helpful.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 19:41:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manual-failback-for-pbf/m-p/75007#M41856</guid>
      <dc:creator>cburke</dc:creator>
      <dc:date>2016-03-21T19:41:15Z</dc:date>
    </item>
  </channel>
</rss>

