<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBF Rule not being hit in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280014#M75815</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/102651"&gt;@WhiteKnight&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Hmm, that seems really odd. The only other reason I would suspect this to not work is if you were trying to utilize PBF for a globalprotect client. Outside of that you might want to open a ticket with TAC.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jul 2019 17:42:59 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-07-30T17:42:59Z</dc:date>
    <item>
      <title>PBF Rule not being hit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/279981#M75803</link>
      <description>&lt;P&gt;I am experiencing an issue with one of our PAN devices, which is a PA-500 running OS 7.0.19. I have created a new PBF rule to forward traffic from a certain subnet to the inside interface of our edge router. I have several other rules pointing other subnets at the same interface which work fine. The PBF rule did not seem to work (yes it is commited). So, I ran the test from the CLI as below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone/Interface: Zone2&lt;/P&gt;&lt;P&gt;Source Address: 10.80.80.0/24 (not real IP)&lt;/P&gt;&lt;P&gt;Destination Address: Any&lt;/P&gt;&lt;P&gt;Application: Any&lt;/P&gt;&lt;P&gt;Service: Any&lt;/P&gt;&lt;P&gt;Action: Forward&lt;/P&gt;&lt;P&gt;Egress Interface: Ethernet 1/2&lt;/P&gt;&lt;P&gt;Next hop: 12.12.12.1 (not real IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From CLI - test pbf-policy-match protocol 6 from Zone2 source 10.80.80.15 destination 8.8.8.8 destination-port 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The results: "No rule matched"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea what can cause this?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 12:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/279981#M75803</guid>
      <dc:creator>WhiteKnight</dc:creator>
      <dc:date>2019-07-30T12:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Rule not being hit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280007#M75811</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/102651"&gt;@WhiteKnight&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Just for fun, can you try setting the source as a single IP and then running your tests again?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 16:31:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280007#M75811</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-30T16:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Rule not being hit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280011#M75812</link>
      <description>&lt;P&gt;I was actually just trying that. I have a test box sitting on that subnet now. The rule is now set for the entire subnet as well as the single IP address. I didn't try the rule with the single IP and remove the subnet. I'll try that now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: I edited to rule to have the source as a single IP. It still results in "No rule matched"&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 17:31:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280011#M75812</guid>
      <dc:creator>WhiteKnight</dc:creator>
      <dc:date>2019-07-30T17:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Rule not being hit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280012#M75813</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/102651"&gt;@WhiteKnight&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;And just to verify, have you looked for any validation errors with you having too many PBF entries? I know that our old 4000s back in the day could handle more than a few, so I doubt you are reaching the limit, but it might be worth checking.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 17:35:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280012#M75813</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-30T17:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Rule not being hit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280013#M75814</link>
      <description>&lt;P&gt;I always validate before commiting. When I do validate, there are no errors.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 17:38:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280013#M75814</guid>
      <dc:creator>WhiteKnight</dc:creator>
      <dc:date>2019-07-30T17:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Rule not being hit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280014#M75815</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/102651"&gt;@WhiteKnight&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Hmm, that seems really odd. The only other reason I would suspect this to not work is if you were trying to utilize PBF for a globalprotect client. Outside of that you might want to open a ticket with TAC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 17:42:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280014#M75815</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-30T17:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Rule not being hit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280015#M75816</link>
      <description>&lt;P&gt;Ok, thanks for the feedback. We do have current support but I figured it was worth asking here. Incase I'm completely overlooking something.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 17:46:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-rule-not-being-hit/m-p/280015#M75816</guid>
      <dc:creator>WhiteKnight</dc:creator>
      <dc:date>2019-07-30T17:46:19Z</dc:date>
    </item>
  </channel>
</rss>

