<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBF is working, but I want to exclude GP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245917#M70056</link>
    <description>&lt;P&gt;That didn't work... but the session browser told me a critical thing.&lt;/P&gt;&lt;P&gt;The data was not correctly sent back..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So after thinking with two people, we decided to create this:&lt;BR /&gt;PBF1 - VPN zone to Trust - any any - No PBF&lt;/P&gt;&lt;P&gt;PBF2 - Trust to VPN IP Pool &lt;SPAN&gt;- any any &lt;/SPAN&gt;- No PBF&lt;/P&gt;&lt;P&gt;PBF3 - Trust to Any - Forward Application [Web-Browsing + SSL] to I/F Eth1/1.400, next hop Router Gateway with Monitor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now everything works as expected!&lt;/P&gt;&lt;P&gt;Thank you for your precious time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jan 2019 15:04:19 GMT</pubDate>
    <dc:creator>Joukevanduijsen</dc:creator>
    <dc:date>2019-01-14T15:04:19Z</dc:date>
    <item>
      <title>PBF is working, but I want to exclude GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245843#M70039</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New here and fighting with my new PA-820.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 ISP's and I want to make the best use possible of those two.&lt;/P&gt;&lt;P&gt;So I created a PBF which reroutes HTTP and HTTPS traffic over the 2nd modem.&lt;/P&gt;&lt;P&gt;Now I have speeds over 350mbit/s for clients and not bothering other important server data which I have only 40mbit/s for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So this is all working fine! Until I use GP for VPN.&lt;/P&gt;&lt;P&gt;The HTTP and HTTPS reroute works fine though, but the internal&amp;nbsp;web applications over port 80 and 443 are rerouted aswell.&lt;/P&gt;&lt;P&gt;So every internal webserver will time out. Age out and and is incomplete.&lt;/P&gt;&lt;P&gt;But for example a webserver with a different port (like synology port 5000) will work fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now GP is more important, so i turned off the PBF and everything works now...&lt;/P&gt;&lt;P&gt;But I really want to use our wide bandwith instead of a very narrow one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried everything from tunnel traffic no-pbf rule to DNAT's to stop GP from using the PBF rule.&lt;/P&gt;&lt;P&gt;But maybe I'm overlooking something...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone point me in the right direction?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 09:01:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245843#M70039</guid>
      <dc:creator>Joukevanduijsen</dc:creator>
      <dc:date>2019-01-14T09:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: PBF is working, but I want to exclude GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245850#M70040</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104825"&gt;@Joukevanduijsen&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you share a screenshot of your PBF policy when it was at the undesired state?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 09:07:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245850#M70040</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-01-14T09:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: PBF is working, but I want to exclude GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245852#M70041</link>
      <description>&lt;P&gt;Sure! Here it is!&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reroute.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18255i6A0A68BA38806385/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="reroute.JPG" alt="reroute.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you can see, i've already tried to Negate the VPN pool, but the GP is also directly hooked to trust-zone.&lt;/P&gt;&lt;P&gt;The last IP you see is monitoring, if this IP is not reachable the PBF rule is deactivated.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 09:27:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245852#M70041</guid>
      <dc:creator>Joukevanduijsen</dc:creator>
      <dc:date>2019-01-14T09:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: PBF is working, but I want to exclude GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245853#M70042</link>
      <description>&lt;P&gt;Your PBF rule should only really be applied to destination zone Untrust, that way it will only activate for internet facing traffic where NAT via the two ISPs is actually required. Then, when you try to visit some internal server in destination zone Trust or DMZ the PBF policy won't even be applied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I have done in the past:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source Zone: Trust&lt;/P&gt;&lt;P&gt;Source IP: Any&lt;/P&gt;&lt;P&gt;Destination IP: All RFC 1918 addresses (negate option checked)&lt;/P&gt;&lt;P&gt;Destination Zone: Untrust&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 09:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245853#M70042</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-01-14T09:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: PBF is working, but I want to exclude GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245855#M70044</link>
      <description>&lt;P&gt;Ahh! Thank you! I'm going to try that now&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 09:52:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245855#M70044</guid>
      <dc:creator>Joukevanduijsen</dc:creator>
      <dc:date>2019-01-14T09:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: PBF is working, but I want to exclude GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245917#M70056</link>
      <description>&lt;P&gt;That didn't work... but the session browser told me a critical thing.&lt;/P&gt;&lt;P&gt;The data was not correctly sent back..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So after thinking with two people, we decided to create this:&lt;BR /&gt;PBF1 - VPN zone to Trust - any any - No PBF&lt;/P&gt;&lt;P&gt;PBF2 - Trust to VPN IP Pool &lt;SPAN&gt;- any any &lt;/SPAN&gt;- No PBF&lt;/P&gt;&lt;P&gt;PBF3 - Trust to Any - Forward Application [Web-Browsing + SSL] to I/F Eth1/1.400, next hop Router Gateway with Monitor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now everything works as expected!&lt;/P&gt;&lt;P&gt;Thank you for your precious time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 15:04:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/245917#M70056</guid>
      <dc:creator>Joukevanduijsen</dc:creator>
      <dc:date>2019-01-14T15:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: PBF is working, but I want to exclude GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/427684#M94639</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;Joukevanduijsen!&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was having this issue as well but due to different circumstances. I have a Appliansys Caching Server. All 80 &amp;amp; 443 traffic is routed to that device via a PBF rule. Everything works great except when I'm connected via GlobalProtect VPN. When I'm connected via GP, I can access any device in my network that uses a port other than 80 &amp;amp; 443. When I disable the PBF rule, everything works fine. I've been working with support on this for two weeks without any progress. Your post solved this for me. I just wanted to reply to thank you and confirm this does work!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 05:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-is-working-but-i-want-to-exclude-gp/m-p/427684#M94639</guid>
      <dc:creator>HamiltonUSD</dc:creator>
      <dc:date>2021-08-19T05:04:15Z</dc:date>
    </item>
  </channel>
</rss>

