<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Useless PBF warning in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/useless-pbf-warning/m-p/298679#M78239</link>
    <description>&lt;P&gt;I've had the same issue, and I resolved it by adding a "dummy" zone to the shadowed PBF rule, as shown below:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22377i53B9BF5C40BDDB91/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2019 21:24:06 GMT</pubDate>
    <dc:creator>Elmer_Potts</dc:creator>
    <dc:date>2019-11-14T21:24:06Z</dc:date>
    <item>
      <title>Useless PBF warning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useless-pbf-warning/m-p/149094#M49727</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's not an issue.. I just want to share with you this thought&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBF_warning.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8340i6BC727C501DA8B04/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PBF_warning.JPG" alt="PBF_warning.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Warning_Rule.JPG" style="width: 499px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8341iA14BD6337515AFC9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Warning_Rule.JPG" alt="Warning_Rule.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Starting from the fact that the egress interface is NOT a matching criteria.. But I have to configure around 80 VPN tunnel (with their own backup tunnel using pbf option "disable if unreachable") .. so it means I will have 80 warnings.. :,(&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It should be useful to put egress interface in PBF policies as a matching criteria?&lt;/P&gt;&lt;P&gt;What is it your opinion?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;D!Z&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 10:20:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useless-pbf-warning/m-p/149094#M49727</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2017-03-23T10:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Useless PBF warning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useless-pbf-warning/m-p/149295#M49766</link>
      <description>&lt;P&gt;Hi TheRealDiz,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's not possible to put the egress interface as a condition, as the PBF is itself responsible for determining the egress interface (the result cannot be a condition).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Palo Alto, either the PBF or the Routing table determines the egress interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your screenshot I can guess rule 7 is shadowing 8, 3 is shadowing 4. Reason is that the conditions are identical for 3/4 and 7/8. Moreover, rule 8 and rule 4 might not actually trigger if you don't choose the monitor profile correctly or check the box for 'Disable this rule if the next hop/monitor IP is unavailable'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing can be done about the warnings. By the way, how many paths can a single tunnel take? If it's just 2, usually you'd put the main path in the PBF and a backup path in the VR. Do you have 3 paths, 2 via PBF and 1 via VR? If it's 2, configure the backup path in the VR (static route = next hop is backup tunnel interface (no IP req'd)). And, in your PBF choose a monitor profile with the Action - Fail over and uncheck the box for&amp;nbsp;&lt;SPAN&gt;'Disable this rule if the next hop/monitor IP is unavailable'.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 05:51:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useless-pbf-warning/m-p/149295#M49766</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-03-24T05:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Useless PBF warning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useless-pbf-warning/m-p/298679#M78239</link>
      <description>&lt;P&gt;I've had the same issue, and I resolved it by adding a "dummy" zone to the shadowed PBF rule, as shown below:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22377i53B9BF5C40BDDB91/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 21:24:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useless-pbf-warning/m-p/298679#M78239</guid>
      <dc:creator>Elmer_Potts</dc:creator>
      <dc:date>2019-11-14T21:24:06Z</dc:date>
    </item>
  </channel>
</rss>

