<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Based Forwarding (PBF) problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10564#M7779</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It look's like this issue is software related.&lt;/P&gt;&lt;P&gt;After updating to software version 4.1.4. everything worked fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Apr 2012 11:21:30 GMT</pubDate>
    <dc:creator>disti_sarajevo</dc:creator>
    <dc:date>2012-04-06T11:21:30Z</dc:date>
    <item>
      <title>Policy Based Forwarding (PBF) problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10561#M7776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;I’ve got problem with policy based forwarding. I have 2 ISP - traffic to the 1st ISP is forwarded by pbf, to the 2nd – via default route. PBF rule monitors the remote target’s IP and &lt;/SPAN&gt;&lt;SPAN class="hps"&gt;&lt;SPAN lang="EN"&gt;availability&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt; of nexthop address. My question is: how the pbf is checking &lt;/SPAN&gt;&lt;SPAN class="hps"&gt;&lt;SPAN lang="EN"&gt;availability&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt; of the nexthop address. I have sniffer open on nexthop address host but I can’t find any specific traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;In the system log I’ve got many entries like this: “Vsys 1 PBF rule pbf nexthop is DOWN”. How can I debug this ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;While the pbf status is DOWN I can ping nexthop address from &lt;/SPAN&gt;&lt;SPAN class="hps"&gt;&lt;SPAN lang="EN"&gt;adjacent&lt;/SPAN&gt; interface of Palo Alto.&lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 13:25:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10561#M7776</guid>
      <dc:creator>LCMember2683</dc:creator>
      <dc:date>2011-11-14T13:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding (PBF) problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10562#M7777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Should ping from the ISP A interface to the remote network. Are you monitoring the next hop? Also verify that you do not see any drops in the traffic logs for the IP you are monitoring. (denyall may drop this traffic).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2011 17:52:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10562#M7777</guid>
      <dc:creator>dburns</dc:creator>
      <dc:date>2011-11-16T17:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding (PBF) problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10563#M7778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem.&lt;/P&gt;&lt;P&gt;The PBF rule status says that the NextHop is Down but I'm sure it's up and I can ping it via source ping from the device.&lt;/P&gt;&lt;P&gt;Did someone manage to solve this issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2012 11:01:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10563#M7778</guid>
      <dc:creator>disti_sarajevo</dc:creator>
      <dc:date>2012-04-05T11:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding (PBF) problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10564#M7779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It look's like this issue is software related.&lt;/P&gt;&lt;P&gt;After updating to software version 4.1.4. everything worked fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Apr 2012 11:21:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10564#M7779</guid>
      <dc:creator>disti_sarajevo</dc:creator>
      <dc:date>2012-04-06T11:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding (PBF) problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10565#M7780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem.&amp;nbsp; I have a deny all at the bottom of the security rule but Untrust to Untrust.&amp;nbsp; The PBF next hop says it's down and the rule disables the route but the next hop is up.&amp;nbsp; I am on 5.0.1 and this still occurs frequently, every few hours.&amp;nbsp; DOES ANYONE KNOW HOW PBF CHECKS THE NEXT HOP AND WHY IT SAYS DOWN WHEN IT"S UP??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 01:32:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10565#M7780</guid>
      <dc:creator>amansour</dc:creator>
      <dc:date>2013-01-16T01:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding (PBF) problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10566#M7781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can anyone from PAN comment this has been recurring for a few days.&amp;nbsp; I have opened tickets but we and haven't got to a root cause.&amp;nbsp; How does the Egress monitor the next hop as up? Would a static ARP help? There is no pings in packet capture, how does it know this is up or down? It's up but shows down.&amp;nbsp; Does it not come back up after it goes down? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 16:10:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10566#M7781</guid>
      <dc:creator>amansour</dc:creator>
      <dc:date>2013-01-16T16:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding (PBF) problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10567#M7782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All;&amp;nbsp; Finally figured out what it is.&amp;nbsp; So the PBF rule does monitor from the Egress interface configured in the Rule.&amp;nbsp; It will come back up if the next hop is up.&amp;nbsp; The monitor uses PING.&amp;nbsp; My problem was that I was trying to fully mesh active-passive firewalls and connected hubs to both uplinks to from the firewalls to a single uplink for the ISP that was having the problem.&amp;nbsp; When I directly connect the ISP directly to the PAN device the pings stay normal.&amp;nbsp; Time to replace some hubs. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 15:27:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10567#M7782</guid>
      <dc:creator>amansour</dc:creator>
      <dc:date>2013-01-17T15:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding (PBF) problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10568#M7783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You also want to put on "Enforce Symmetric Return" IF you are running dual IPSec tunnels over the PBF the return traffic has to go out the interface it came in on, or the tunnel will stay up but renegotiate constantly. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 23:29:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-pbf-problem/m-p/10568#M7783</guid>
      <dc:creator>amansour</dc:creator>
      <dc:date>2013-01-17T23:29:59Z</dc:date>
    </item>
  </channel>
</rss>

