<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Based Forwarding vs Security Rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162959#M52804</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;BR /&gt;Your explanation helped me understand it better.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;PS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2017 14:27:06 GMT</pubDate>
    <dc:creator>psharma</dc:creator>
    <dc:date>2017-06-23T14:27:06Z</dc:date>
    <item>
      <title>Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162793#M52758</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not quite sure about the difference between rules created under 'Policy based forwarding' and 'Security' under Policies tab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone please help understand how are the rules different that are created under security and Policy based forwarding?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;PS&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 17:53:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162793#M52758</guid>
      <dc:creator>psharma</dc:creator>
      <dc:date>2017-06-22T17:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162802#M52760</link>
      <description>&lt;P&gt;PBF rules are checked before routing table and if any match then routing table is skipped.&lt;/P&gt;&lt;P&gt;So Security policies are to permit or deny traffic and PBF rules are used to decide where traffic should go to.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 18:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162802#M52760</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-06-22T18:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162805#M52761</link>
      <description>&lt;P&gt;ok, now i understand the difference between PBF and security rues but what is the need for PBF?&lt;/P&gt;&lt;P&gt;Is the Forwarding table alone not sufficient enough?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically, why do we need PBF if we already have routing tables?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;PS&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 19:06:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162805#M52761</guid>
      <dc:creator>psharma</dc:creator>
      <dc:date>2017-06-22T19:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162809#M52763</link>
      <description>&lt;P&gt;Routing is based on "destination". &amp;nbsp;To get to y.y.y.y send to next-hop z.z.z.z&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy-based Forwarding adds Source IP address to the routing decision. &amp;nbsp;This allows you to make routing decisions based on where the traffic is coming from - not just based on the destination. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One example:&lt;/P&gt;&lt;P&gt;&amp;nbsp; PBF: "Forward all guest wireless traffic through the cheap local cablemodem/ISP"&lt;/P&gt;&lt;P&gt;&amp;nbsp; Routing: &amp;nbsp;"Send all corporate traffic through the expensive MPLS circuit"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another example:&lt;/P&gt;&lt;P&gt;&amp;nbsp; PBF Rule 1: "Forward half of my users via ISP1"&lt;/P&gt;&lt;P&gt;&amp;nbsp; PBF Rule 2: "Forward the other half of my users via ISP2"&lt;/P&gt;&lt;P&gt;&amp;nbsp; PBF Rule 3: "Forward all users via ISP1" (in case ISP2 is down)&lt;/P&gt;&lt;P&gt;&amp;nbsp; PBF Rule 4: "Forward all users via ISP2" (in case ISP1 is down)&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 19:30:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162809#M52763</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-06-22T19:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162826#M52769</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65744"&gt;@psharma&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There are quite a few use cases for PBF that would dictate that certain traffic is sent to a certain destination. PBF lets you specify an application, which wouldn't be possible if you are using just the routing table.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 20:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162826#M52769</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-22T20:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162828#M52771</link>
      <description>&lt;P&gt;from this example:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One example:&lt;/P&gt;&lt;P&gt;&amp;nbsp; PBF: "Forward all guest wireless traffic through the cheap local cablemodem/ISP"&lt;/P&gt;&lt;P&gt;&amp;nbsp; Routing: &amp;nbsp;"Send all corporate traffic through the expensive MPLS circuit"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not feel any real difference between PBF and routing from the example above.&lt;/P&gt;&lt;P&gt;But, i do understand that PBF is used when you are deciding where to route based on the source and not on the destination as we typically do in routing.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;However, in your example, it looks like you are deciding based on source for both. then how come the corporate one will be taken as routing and not PBF?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 20:55:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162828#M52771</guid>
      <dc:creator>psharma</dc:creator>
      <dc:date>2017-06-22T20:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162830#M52773</link>
      <description>&lt;P&gt;In the first example, "forward guest wireless traffic" is a single PBF rule, where the 2nd rule (send everything else via MPLS) happens in the virtual router / default route. &amp;nbsp;I'll tweak the example to be a little more clear:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;U&gt;&lt;STRONG&gt;PBF&lt;/STRONG&gt;&lt;/U&gt;: "Forward all guest wireless traffic through the cheap local cablemodem/ISP"&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;U&gt;&lt;STRONG&gt;Routing&lt;/STRONG&gt;&lt;/U&gt;: &amp;nbsp;"Send all traffic through the default route (MPLS circuit)"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My mistake for saying "all corporate traffic" - I meant "all traffic" that didn't match the PBF rule. &amp;nbsp;Hope that clears it up. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 21:01:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162830#M52773</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-06-22T21:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162840#M52775</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;PBF lets you specify an application, which wouldn't be possible if you are using just the routing table.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using Application for match criteria in a Policy-Based Forwarding policy is not recommended. &amp;nbsp;Palo Alto Networks recommends using a service object instead, if possible. &amp;nbsp;Not to say that Application-based PBF doesn't work, but there are a handful of caveats to be aware of:&lt;/P&gt;&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/pbf#_13619" target="_self"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/pbf#_13619&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That being said, the example is helpful as it's a great difference between PBF and Routing. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 21:08:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162840#M52775</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-06-22T21:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162841#M52776</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65744"&gt;@psharma&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You would use routing because it would state something along the lines of all traffic should go out the MPLS circut; then with PBF you specify with guest wireless traffic goes out the ISP gear.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Further example would be if I had a route that stated 10.191.0.0/16 needs to go to a specific circuit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Say that I have my GIS users on 10.191.80.0/25 and for a undetermined amount of time I need to route them through a different circuit do to a potential litigation hold (sigh); I would find that easier to do with a PBF which is easy to create and remove on the fly rather than messing around with my routing table and breaking subnets out of my 10.191.0.0/16 range.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 21:08:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162841#M52776</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-22T21:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162842#M52777</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That's why I put it in; missing the first hand-full of packets until you actually get identified can be a pain, but thankfully we now have that awesome application cache so it's less of an issue &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 21:09:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162842#M52777</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-22T21:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162958#M52803</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for beautifully explaining it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate it. Now i have good understanding of the basic differences.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;PS&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 14:25:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162958#M52803</guid>
      <dc:creator>psharma</dc:creator>
      <dc:date>2017-06-23T14:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding vs Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162959#M52804</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;BR /&gt;Your explanation helped me understand it better.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;PS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 14:27:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-vs-security-rules/m-p/162959#M52804</guid>
      <dc:creator>psharma</dc:creator>
      <dc:date>2017-06-23T14:27:06Z</dc:date>
    </item>
  </channel>
</rss>

