<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic When should I use &amp;quot;enforce symmetric return&amp;quot; in the PBF rules? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162961#M52805</link>
    <description>&lt;P&gt;What is the purpose of this setting? Doesn't all traffic go out the same route as it came in, anyway?&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2017 14:48:29 GMT</pubDate>
    <dc:creator>Maxstr</dc:creator>
    <dc:date>2017-06-23T14:48:29Z</dc:date>
    <item>
      <title>When should I use "enforce symmetric return" in the PBF rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162961#M52805</link>
      <description>&lt;P&gt;What is the purpose of this setting? Doesn't all traffic go out the same route as it came in, anyway?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 14:48:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162961#M52805</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2017-06-23T14:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: When should I use "enforce symmetric return" in the PBF rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162970#M52807</link>
      <description>&lt;P&gt;The only use case that I can think of off hand is asymetrical routing, this would ensure that your PBF rule actually gets the return traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Gives a nice breakdown of why you would actually use it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Symmetric-Return/ta-p/59374" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Symmetric-Return/ta-p/59374&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 14:58:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162970#M52807</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-23T14:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: When should I use "enforce symmetric return" in the PBF rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162973#M52810</link>
      <description>That article mentions dual ISP's, and I do have dual ISP with PBF rules for failover. So traffic that comes in one ISP goes out the same ISP.&lt;BR /&gt;&lt;BR /&gt;So by enabling this option, I can have traffic coming in one IP, and out a different IP? Like in ISP1 and out ISP2? That sounds exactly the opposite of enforcing symmetric return.</description>
      <pubDate>Fri, 23 Jun 2017 15:24:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162973#M52810</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2017-06-23T15:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: When should I use "enforce symmetric return" in the PBF rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162988#M52812</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/25857"&gt;@Maxstr&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;is right. The only case where you would need to use Symmetric Return is to ensure that the traffic returns through the same path where it originally came in. Regardless of having dual ISP you still can use this feature as all you want to achieve is to make sure the traffic is kept in a symmetrical fashion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although the article below mentions two ISPs, the only reason the author mentions that is because he want to show that redundancy is possible by configuring duplicated security and NAT policies, but notice that he only needed to configure one set of PBF policies to achieve what he wants which is to keep the traffic symmetrical.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Symmetric-Return/ta-p/59374" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Symmetric-Return/ta-p/59374&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now responding your question:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Doesn't all traffic go out the same route as it came in, anyway? The answer here is depend. And the reason I say that is because it depends on what the backend server default gateway is. Imagine that the traffic coming in is going to a server, which the default gateway is not the firewall, but a router. It means that the response out to the client will source from a different IP, which will incur ina broken (Rejected) connection.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The below link is for an F5 Networks article that explains this scenario, and it tells you exactly what the behavior of an asymmetrical routing issue would be especially when dealing with NAT or in our case here PBF.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm_configuration_guide_10_0_0/ltm_snat.html" target="_blank"&gt;https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm_configuration_guide_10_0_0/ltm_snat.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 18:02:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162988#M52812</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-23T18:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: When should I use "enforce symmetric return" in the PBF rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162992#M52814</link>
      <description>&lt;P&gt;Thanks for the reply. The one thing that still confuses me is that when you enable Enforce Symmetric on the PBF rule, it opens up the box below it titled "Next hop address list" on the bottom.&lt;/P&gt;&lt;P&gt;If it were enforcing the same return path, why would you need to provide additional next-hop IP's?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nexthop.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9904iE735036EA9526F1C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="nexthop.PNG" alt="nexthop.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 18:56:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/162992#M52814</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2017-06-23T18:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: When should I use "enforce symmetric return" in the PBF rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/163031#M52822</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/25857"&gt;@Maxstr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There's a part in the above article that mentions all of that but,&lt;/P&gt;&lt;P&gt;'&lt;SPAN&gt;Configure Next Host IP address if Destination Network is not directly connected'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You have to remember that a PBF with symmetric return is essentially a routing policy that is simply processed pre-routing table. So you have to essentially provide all available routing options for people that actually need them to be present.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 20:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/163031#M52822</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-23T20:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: When should I use "enforce symmetric return" in the PBF rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/374452#M89060</link>
      <description>&lt;P&gt;sorry for digging out this years old threat but I have been trying to find some more detailled information on this but it seems some in depth insight of how this works is difficult to find...&lt;/P&gt;&lt;P&gt;Of course shortly after posting this I found the technical answer:&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/policy-based-forwarding/pbf/egress-path-and-symmetric-return.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/policy-based-forwarding/pbf/egress-path-and-symmetric-return.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So for anyone who is/was wondering how its actually done, its explained there... answered all my open questions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 09:56:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/374452#M89060</guid>
      <dc:creator>CLIq</dc:creator>
      <dc:date>2020-12-15T09:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: When should I use "enforce symmetric return" in the PBF rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/1223901#M123658</link>
      <description>&lt;P&gt;Both those article links are now dead.&amp;nbsp; I'm trying to hunt them down by topic...&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 16:38:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-should-i-use-quot-enforce-symmetric-return-quot-in-the-pbf/m-p/1223901#M123658</guid>
      <dc:creator>Darin-May</dc:creator>
      <dc:date>2025-03-14T16:38:57Z</dc:date>
    </item>
  </channel>
</rss>

