<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBF SMTP for both ISP1/ISP2 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-smtp-for-both-isp1-isp2/m-p/155454#M51121</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/8908"&gt;@x&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;do you have a single Virtual Router with attached both ISPs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggest you to follow this article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to follow this article without the VPN parts.&lt;/P&gt;&lt;P&gt;I have already done the same configuration you described and it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;Jacopo&lt;/P&gt;</description>
    <pubDate>Mon, 08 May 2017 08:01:55 GMT</pubDate>
    <dc:creator>Jacopo_Vigano</dc:creator>
    <dc:date>2017-05-08T08:01:55Z</dc:date>
    <item>
      <title>PBF SMTP for both ISP1/ISP2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-smtp-for-both-isp1-isp2/m-p/155440#M51120</link>
      <description>&lt;P&gt;I'm wondering if anyone has a similar setup and got it working. I'd like to have both SMTP services enabled on two ISPs for load-balancing and redundancy. I tried using PBF but couldn't get it working. It seems SMTP for ISP1 works fine but SMTP for ISP2 comes into the firewall but the application is incomplete. Which tells me the 3 way handshake is not completing. I took a pcap and didn't see any drops however. &amp;nbsp;I followed the articles below as guidelines:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Symmetric-Return/ta-p/59374" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Symmetric-Return/ta-p/59374&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;eth1/1.2 ISP1 1.1.1.1&lt;/P&gt;&lt;P&gt;eth 1/1.3 ISP2 2.2.2.2&lt;/P&gt;&lt;P&gt;Inside 10.1.1.1 - STMP server is 10.1.1.25&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security allows SMTP traffic to both ISPs&lt;/P&gt;&lt;P&gt;NATs for both ISPs (inbound and outbound on SMTP service)&lt;/P&gt;&lt;P&gt;Default route is 2.2.2.2&lt;/P&gt;&lt;P&gt;PBF to force symmetric return if interface comes in from from eth1/1.3&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF forces browsing to 1.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what I can tell all the policies that I've defined are being hit and symmetric return is being acknowledged but the traffic is not going through. Traffic for ISP1 is identified as SMTP but for ISP2, it is incomplete.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've got a TAC opened but also wanted to check with our awesome community!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks folks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2017 21:00:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-smtp-for-both-isp1-isp2/m-p/155440#M51120</guid>
      <dc:creator>x</dc:creator>
      <dc:date>2017-05-07T21:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: PBF SMTP for both ISP1/ISP2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-smtp-for-both-isp1-isp2/m-p/155454#M51121</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/8908"&gt;@x&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;do you have a single Virtual Router with attached both ISPs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggest you to follow this article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to follow this article without the VPN parts.&lt;/P&gt;&lt;P&gt;I have already done the same configuration you described and it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;Jacopo&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 08:01:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-smtp-for-both-isp1-isp2/m-p/155454#M51121</guid>
      <dc:creator>Jacopo_Vigano</dc:creator>
      <dc:date>2017-05-08T08:01:55Z</dc:date>
    </item>
  </channel>
</rss>

