<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBFand Default route in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbfand-default-route/m-p/92948#M43744</link>
    <description>&lt;P&gt;outbound traffic may be hitting an incorrect NAT rule as the zones are identical, what is the output of "show session id &amp;lt;id&amp;gt;" of a failing session the moment the default route should be used? is the egress interface correct, is the source NAT accurate,...&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jun 2016 07:48:44 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-06-28T07:48:44Z</dc:date>
    <item>
      <title>PBFand Default route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbfand-default-route/m-p/86851#M43731</link>
      <description>&lt;P&gt;In our orginazation, we have dual ISP and PAN firewalls. We have configured PBF with ISP 1 and default route for ISP 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both ISP interfaces on Pan firewall is same zone called untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example : &amp;nbsp;ethernet 1/11&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ethernet 1/11.200 ----- 192.168.1.1/30 &amp;nbsp;- untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ethernet 1/11.250 ------172.16.10.1/30 - untrust&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When primary ISP goes down, the traffic is not taking default route. if we configure another zone like untrust1 to second ISP&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;when the PBF fails, traffic will take default route, Is something we need configure here if the both the ISP's are in same zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 12:16:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbfand-default-route/m-p/86851#M43731</guid>
      <dc:creator>Venuprasad</dc:creator>
      <dc:date>2016-06-15T12:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: PBFand Default route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbfand-default-route/m-p/92948#M43744</link>
      <description>&lt;P&gt;outbound traffic may be hitting an incorrect NAT rule as the zones are identical, what is the output of "show session id &amp;lt;id&amp;gt;" of a failing session the moment the default route should be used? is the egress interface correct, is the source NAT accurate,...&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2016 07:48:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbfand-default-route/m-p/92948#M43744</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-06-28T07:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: PBFand Default route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbfand-default-route/m-p/92965#M43750</link>
      <description>&lt;P&gt;In PBF have you configured monitoring option ( like 8.8.8.8) this wll give info to firewall that ISP 1 is down use routing table&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2016 08:26:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbfand-default-route/m-p/92965#M43750</guid>
      <dc:creator>Roby_Sreejith</dc:creator>
      <dc:date>2016-06-28T08:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: PBFand Default route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbfand-default-route/m-p/93230#M43774</link>
      <description>&lt;P&gt;Yes as per Roby's comment you need the monitor or PAN will still execute the PBF policy as it does not know your ISP 1 is down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could easily test this by putting in a single (test) source IP in the PBF and set a monitor which does not respond, then do a traceroute from the source IP. You should see the route go via ISP2.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2016 21:22:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbfand-default-route/m-p/93230#M43774</guid>
      <dc:creator>ShannonRowe</dc:creator>
      <dc:date>2016-06-28T21:22:44Z</dc:date>
    </item>
  </channel>
</rss>

