<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does PBF work across different virtual routers? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/does-pbf-work-across-different-virtual-routers/m-p/127000#M46579</link>
    <description>&lt;P&gt;Hi CMG,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes this works fine assuming the following;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;both interfaces part or same zone&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;asymmetric routing not in play&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sec policies allowing same&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Run the following commands when testing; &amp;nbsp;{apply filters for the source &amp;amp; dst you are testing with.. so counters relevant }&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;show counter global filter packet-filter yes delta yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;use the following articles if getting droppped due to asymmetric R&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/SYN-ACK-Issues-with-Asymmetric-Routing/ta-p/54090" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/SYN-ACK-Issues-with-Asymmetric-Routing/ta-p/54090&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Issues-with-Asymmetric-Routing/ta-p/65456" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Issues-with-Asymmetric-Routing/ta-p/65456&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;run the following cmds to test the pbf rule matches whats expected aswell, replacing IPs as required. Ping protocol number is 1 and what I used for a quick test..&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@PA-3000&amp;gt; test pbf-policy-match application any from untrust destination 172.25.5.239 protocol 1 source 172.25.4.6&lt;/P&gt;&lt;P&gt;test {&lt;BR /&gt;id 1;&lt;BR /&gt;from untrust;&lt;BR /&gt;source any;&lt;BR /&gt;destination any;&lt;BR /&gt;user any;&lt;BR /&gt;application/service any/any/any/any;&lt;BR /&gt;action Forward;&lt;BR /&gt;symmetric-return no;&lt;BR /&gt;forwarding-egress-IF/VSYS ethernet1/2;&lt;BR /&gt;next-hop 0.0.0.0;&lt;BR /&gt;terminal no;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Robert D&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Nov 2016 11:21:19 GMT</pubDate>
    <dc:creator>DonohoeRobert</dc:creator>
    <dc:date>2016-11-17T11:21:19Z</dc:date>
    <item>
      <title>Does PBF work across different virtual routers?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-pbf-work-across-different-virtual-routers/m-p/126538#M46522</link>
      <description>&lt;P&gt;Does PBF work across different virtual routers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i.e Will a PBF rule work if the incoming packet is received on an interface associated with one virtual router, and the rule tells it to go out an interface associated with a different virtual router?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm assuming it should.. just wanted to clarify..&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 21:05:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-pbf-work-across-different-virtual-routers/m-p/126538#M46522</guid>
      <dc:creator>CMG</dc:creator>
      <dc:date>2016-11-15T21:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Does PBF work across different virtual routers?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-pbf-work-across-different-virtual-routers/m-p/127000#M46579</link>
      <description>&lt;P&gt;Hi CMG,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes this works fine assuming the following;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;both interfaces part or same zone&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;asymmetric routing not in play&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sec policies allowing same&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Run the following commands when testing; &amp;nbsp;{apply filters for the source &amp;amp; dst you are testing with.. so counters relevant }&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;show counter global filter packet-filter yes delta yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;use the following articles if getting droppped due to asymmetric R&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/SYN-ACK-Issues-with-Asymmetric-Routing/ta-p/54090" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/SYN-ACK-Issues-with-Asymmetric-Routing/ta-p/54090&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Issues-with-Asymmetric-Routing/ta-p/65456" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Issues-with-Asymmetric-Routing/ta-p/65456&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;run the following cmds to test the pbf rule matches whats expected aswell, replacing IPs as required. Ping protocol number is 1 and what I used for a quick test..&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@PA-3000&amp;gt; test pbf-policy-match application any from untrust destination 172.25.5.239 protocol 1 source 172.25.4.6&lt;/P&gt;&lt;P&gt;test {&lt;BR /&gt;id 1;&lt;BR /&gt;from untrust;&lt;BR /&gt;source any;&lt;BR /&gt;destination any;&lt;BR /&gt;user any;&lt;BR /&gt;application/service any/any/any/any;&lt;BR /&gt;action Forward;&lt;BR /&gt;symmetric-return no;&lt;BR /&gt;forwarding-egress-IF/VSYS ethernet1/2;&lt;BR /&gt;next-hop 0.0.0.0;&lt;BR /&gt;terminal no;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Robert D&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 11:21:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-pbf-work-across-different-virtual-routers/m-p/127000#M46579</guid>
      <dc:creator>DonohoeRobert</dc:creator>
      <dc:date>2016-11-17T11:21:19Z</dc:date>
    </item>
  </channel>
</rss>

