<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding streaming traffic to a second Palo in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133230#M47182</link>
    <description>&lt;P&gt;Both firewalls are on the same LAN, the default gateway of the LAN clients is the first firewall. Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Dec 2016 11:37:55 GMT</pubDate>
    <dc:creator>Jordan_Roebuck</dc:creator>
    <dc:date>2016-12-16T11:37:55Z</dc:date>
    <item>
      <title>Forwarding streaming traffic to a second Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133219#M47178</link>
      <description>&lt;P&gt;Hi all. We have two Palo 3020s, each connected to a different ISP. At the moment the 1st firewall handles all our LAN internet based traffic, whereas the second firewall is mainly used for our VPN connections. We're looking at forwarding streaming traffic from the 1st firewall to the second firewall, to reduce the bandwidth usage on our primary ISP connection. I've been looking into configuring Policy Based Forwarding to achieve this, but most examples I see of this only use one firewall connected to multiple ISP connections. We're unable to connect our first firewall to the secondary ISP connection. Looking for advice on how I can forward this traffic through a seconadry Palo.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 10:42:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133219#M47178</guid>
      <dc:creator>Jordan_Roebuck</dc:creator>
      <dc:date>2016-12-16T10:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding streaming traffic to a second Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133226#M47179</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are these firewall on the same LAN but got two different ISPs connections? What is the default gateway for your LAN clients?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 13:44:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133226#M47179</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-16T13:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding streaming traffic to a second Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133230#M47182</link>
      <description>&lt;P&gt;Both firewalls are on the same LAN, the default gateway of the LAN clients is the first firewall. Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 11:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133230#M47182</guid>
      <dc:creator>Jordan_Roebuck</dc:creator>
      <dc:date>2016-12-16T11:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding streaming traffic to a second Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133234#M47184</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the confirmation. Havent done much &amp;nbsp;of PBF but l think you can specify in the policy for the specific traffic to be fowarded to the 2nd firewall, &amp;nbsp;then that firewall will use its ISP connection to get out.&lt;/P&gt;&lt;P&gt;Second option would be&amp;nbsp;to have a router/Layer 3 device as DG and do PBF there so it will deside which traffic to send where (1st or 2nd FW)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 13:45:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133234#M47184</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-16T13:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding streaming traffic to a second Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133235#M47185</link>
      <description>&lt;P&gt;PBF will work just fine if you consider for each firewall the 'other firewall' is an ISP instead of 'your firewall'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eg. on firewall 1 you'd need to set up pbf routing as if firewall 2 is the second ISP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you include your topology, this may help get the creative juices flowing also &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 12:36:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133235#M47185</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-12-16T12:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding streaming traffic to a second Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133261#M47189</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See below for a crude diagram of the topolgy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBF.jpg" style="width: 763px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6939iC38B05F18500EBB8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PBF.jpg" alt="PBF.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a test I configured policy based forwarding on P1 with source as the inside traffic (1/2) with 1/6 as the egress interface and 192.168.255.254 as the next hop, I also enforced symetric return. This doesn't work as the traffic still leaves 1/1 (ISP1) on the first Palo.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 14:12:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133261#M47189</guid>
      <dc:creator>Jordan_Roebuck</dc:creator>
      <dc:date>2016-12-16T14:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding streaming traffic to a second Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133264#M47190</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx for the diagramm. Did you try to allow any traffic? Just test with any as a destination. &amp;nbsp;Can you post screen shots of the PBF?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 14:29:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-streaming-traffic-to-a-second-palo/m-p/133264#M47190</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-16T14:29:39Z</dc:date>
    </item>
  </channel>
</rss>

