<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Subinterfaces and Policy based routing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/202456#M59730</link>
    <description>&lt;P&gt;Since you enabled PBR on the switch behind the firewall, you may need to add routing or PBF with symmetric return on the firewall (192.168.0.0/24 via 192.168.254.&amp;lt;switch interface&amp;gt;)&lt;/P&gt;
&lt;P&gt;The firewall may now want to try and route return packets out of 172.16.1.141 which will cause all kinds of problems&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2018 08:25:35 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-02-27T08:25:35Z</dc:date>
    <item>
      <title>Subinterfaces and Policy based routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/202428#M59728</link>
      <description>&lt;P&gt;Hi, so I've configured a new L3 subinterface on an existing L3 interface, both with IP addresses and I thought it was going to work. I've got a PBR rule in place on the previous hop, a HP switch, which diverts some traffic to this new subinterface. I can see the selected traffic allowed out from the Palo's traffic monitor logs but, from the client end, routing through the new subinterface I'm not getting responses back. A traceroute from the client to outside (or even the subinterface's primary interface) result in a response from the subinterface but no further.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Library network PBR plan.jpg" style="width: 627px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13986i5958655DF386D5B0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Library network PBR plan.jpg" alt="Library network PBR plan.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-02-27_161058.jpg" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13987iCB8738BB55B4D601/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-02-27_161058.jpg" alt="2018-02-27_161058.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Out of desperation I added a static route on the Palo to ensure the return packets know how to get back but it's still not working. I've added a snippet of the network for a visual representation. Any ideas what I might have missed?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 05:20:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/202428#M59728</guid>
      <dc:creator>michelle79</dc:creator>
      <dc:date>2018-02-27T05:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces and Policy based routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/202456#M59730</link>
      <description>&lt;P&gt;Since you enabled PBR on the switch behind the firewall, you may need to add routing or PBF with symmetric return on the firewall (192.168.0.0/24 via 192.168.254.&amp;lt;switch interface&amp;gt;)&lt;/P&gt;
&lt;P&gt;The firewall may now want to try and route return packets out of 172.16.1.141 which will cause all kinds of problems&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 08:25:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/202456#M59730</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-27T08:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces and Policy based routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/202457#M59731</link>
      <description>&lt;P&gt;Just a couple of questions for clarity for me and hopefully others:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Is the outgoing traffic having NAT applied to it? It wasn't clear from the logs or config you provided whether the new subnet is being hidden correctly behind your external address.&lt;/P&gt;&lt;P&gt;2) Have you performed a packet capture to confirm that the traffic is being received back to the firewall and then what interfaces its leaving on the firewall (looking at the source mac of the return packet on the transmit pcap)?&lt;/P&gt;&lt;P&gt;3)&amp;nbsp;Have you checked the counters on the firewall (apply packet capture filters then run 'show counter global filter severity drop packet-filter yes delta yes' whilst generating traffic to make sure none of it is being dropped silently.&lt;/P&gt;&lt;P&gt;4)&amp;nbsp;If the above fails, have you looked at performing a flow debug basic to confirm if the return traffic is leaving the correct interface and doesn't show an drops?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a couple of ideas for next steps for you. Please leave an update with what you find&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 08:39:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/202457#M59731</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-02-27T08:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces and Policy based routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/203447#M59940</link>
      <description>&lt;P&gt;Hi JamesWW,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for taking the time to respond. Sorry it's taken a while to get back to you, I'm only part time here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per the post by reaper, I ended up adding a PBF rule to the Palo to route traffic destined for the public subnet through to the public interface and that's worked. Thanks again for the time you took to help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Michelle&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 04:17:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/203447#M59940</guid>
      <dc:creator>michelle79</dc:creator>
      <dc:date>2018-03-05T04:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces and Policy based routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/203448#M59941</link>
      <description>&lt;P&gt;Hi reaper, I had suspected that this might be the case but wasn't&amp;nbsp;really sure if it would be necessary. Anyways, I tried it and it works you little ripper!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 04:14:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-and-policy-based-routing/m-p/203448#M59941</guid>
      <dc:creator>michelle79</dc:creator>
      <dc:date>2018-03-05T04:14:33Z</dc:date>
    </item>
  </channel>
</rss>

