<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPv6 over backup interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipv6-over-backup-interface/m-p/258679#M73356</link>
    <description>&lt;P&gt;A couple things you may be able to test to see what's going on:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Dump the fib table. It won't help for your PBF rule, but since your VR has a static route it should show that correctly:&lt;/P&gt;&lt;PRE&gt;&amp;gt; show routing route&lt;/PRE&gt;&lt;P&gt;2. Test the routing to see what the firewall thinks the correct route should be:&lt;/P&gt;&lt;PRE&gt;&amp;gt; test routing fib-lookup virtual-router your_vr_name ip 2a00:1450:4001...&lt;/PRE&gt;&lt;P&gt;The virtual router will always take a more specific route, so make sure your eth1/1 route doesn't have a more specific IPv6 route that is overriding your static route. It may also be helpful to see what your static route and PBF policy does (if you can sanitize it for public consumption here in the forums).&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2019 20:27:35 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2019-04-24T20:27:35Z</dc:date>
    <item>
      <title>IPv6 over backup interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipv6-over-backup-interface/m-p/258643#M73344</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;I have IPv6 over my backup ISP (dual PA 3020s). &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;I am trying to route all IPv6 traffic over that interface but not having much luck passing any IPv6 through the PA. If I ping6 internal and external hosts from the PA itself it works. If I try to ping/traceroute from behind the PAN at the core or from outside the PAN it doesn't work. I have policies in both directions and I see when I send traffic from behind the PAN (from the core) the PAN is routing it out the primary interface eth1/2 which won't work.&amp;nbsp; I need it to go out eth1/3.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;This is what I have tried:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;Static route for IPv6 default route pointing to backup interface + next hop of IPv6 WAN&lt;/LI&gt;&lt;LI&gt;PBF for IPv6 source traffic forwarded to backup interface + next hop IPv6 WAN&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;Neither worked and I am still seeing IPv6 packets being routed out the primary interface. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;Anyone have any ideas?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;Trust &amp;gt; Untrust (wrong int):&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;&lt;A href="https://imgur.com/77ht8L7" target="_blank" rel="noopener"&gt;https://imgur.com/77ht8L7&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;Untrust &amp;gt; Trust: (right int):&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;&lt;A href="https://imgur.com/dOiv54J" target="_blank"&gt;https://imgur.com/dOiv54J&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 24 Apr 2019 17:21:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipv6-over-backup-interface/m-p/258643#M73344</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2019-04-24T17:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 over backup interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipv6-over-backup-interface/m-p/258679#M73356</link>
      <description>&lt;P&gt;A couple things you may be able to test to see what's going on:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Dump the fib table. It won't help for your PBF rule, but since your VR has a static route it should show that correctly:&lt;/P&gt;&lt;PRE&gt;&amp;gt; show routing route&lt;/PRE&gt;&lt;P&gt;2. Test the routing to see what the firewall thinks the correct route should be:&lt;/P&gt;&lt;PRE&gt;&amp;gt; test routing fib-lookup virtual-router your_vr_name ip 2a00:1450:4001...&lt;/PRE&gt;&lt;P&gt;The virtual router will always take a more specific route, so make sure your eth1/1 route doesn't have a more specific IPv6 route that is overriding your static route. It may also be helpful to see what your static route and PBF policy does (if you can sanitize it for public consumption here in the forums).&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 20:27:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipv6-over-backup-interface/m-p/258679#M73356</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-04-24T20:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 over backup interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipv6-over-backup-interface/m-p/258696#M73360</link>
      <description>&lt;P&gt;I got it working.&amp;nbsp; I simply moved the PBF to the top of my PBF list and did not specify a next hop interface (eth 1/3) on the static route and it started working.&amp;nbsp; Which is weird because that PBF rule was the only one referrencing any IPv6 traffic so I figured it would match it regardless of where it resided in the list.&amp;nbsp; Not sure which one of this allowed it start working but it is now.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="pbf-ipv6.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19712i183117BED515263B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pbf-ipv6.JPG" alt="pbf-ipv6.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="route-ipv6.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19713i707A4DB49712AEF4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="route-ipv6.JPG" alt="route-ipv6.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 21:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipv6-over-backup-interface/m-p/258696#M73360</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2019-04-24T21:19:36Z</dc:date>
    </item>
  </channel>
</rss>

