<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBF Monitor Target in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/309837#M80258</link>
    <description>&lt;P&gt;hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF rule is not applied when the monitoring host is unreachable. If no IP address is specified for monitoring,&amp;nbsp; then the next hop IP is monitored. When a PBF rule is configured with monitoring enabled,&amp;nbsp; the egress interface send keepalives to monitoring IP or next hop.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2020 16:18:22 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2020-02-06T16:18:22Z</dc:date>
    <item>
      <title>PBF Monitor Target</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/309821#M80254</link>
      <description>&lt;P&gt;Scenario is dual-ISP scenario using PBF to connect via primary ISP but switch to secondary if primary goes down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a Policy Based Forwarding rule in the Monitor section of the Forwarding tab, there are 2 checkboxes: one for Monitoring itself, and the second one labelled "Disable this rule if nexthop/monitor ip is unreachable".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firstly, what is the point of the 2nd "Disable this rule" checkbox? Why would someone leave it unchecked? If we are monitoring connectivity to an external address, and we can't reach it over the egress interface, would we not always want the PBF rule to disable? What scenario would we not want to do this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Secondly, if a monitor IP address is added, does the Palo Alto just check connectivity to that address, or also to the next-hop as well? The checkbox label says "disable this rule if nexthop/monitor is unreachable" which is unclear to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 15:22:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/309821#M80254</guid>
      <dc:creator>TomMeadows</dc:creator>
      <dc:date>2020-02-06T15:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Monitor Target</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/309837#M80258</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF rule is not applied when the monitoring host is unreachable. If no IP address is specified for monitoring,&amp;nbsp; then the next hop IP is monitored. When a PBF rule is configured with monitoring enabled,&amp;nbsp; the egress interface send keepalives to monitoring IP or next hop.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 16:18:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/309837#M80258</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-06T16:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Monitor Target</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/309920#M80276</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So you asked two questions. I'll try and be brief on both:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I really dont have an answer for this. There could be a use case, but cant think of one at the moment.&lt;/LI&gt;&lt;LI&gt;It will only monitor the IP you specifiy, regardless if its next hop or further down the line.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 22:33:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/309920#M80276</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-02-06T22:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Monitor Target</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/311193#M80548</link>
      <description>&lt;P&gt;In dual-ISP scenario without running BGP, I always advise to a customer to add host-based static route to ISP serial IP. This way, no matter what&amp;nbsp; platform/feature/check-box is used, my monitor packet would reach next hop via right egress interface.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 03:33:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/311193#M80548</guid>
      <dc:creator>srogatnev</dc:creator>
      <dc:date>2020-02-14T03:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Monitor Target</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/411997#M92786</link>
      <description>&lt;P&gt;Hi Tom,&lt;BR /&gt;For the first point, if you the objective of the monitoring is to fallback then the Disable option should be checked. However if there is no alternative path, and the objectective is just to detect path failure, then the Disable option should not be checked.&lt;/P&gt;&lt;P&gt;For the second point if there is no monitor "IP Address", it will monitor on the "Next Hop". However if there is monitor IP address it will monitor on it instead of the Next Hop. No need to monitor the next hop separetly as it will be used on the way to the "IP Address" anyways.&lt;BR /&gt;Hope this make sense.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 07:57:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/411997#M92786</guid>
      <dc:creator>WafikMaher</dc:creator>
      <dc:date>2021-06-09T07:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Monitor Target</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/598850#M119106</link>
      <description>&lt;P&gt;&lt;SPAN&gt;PBF rule is not applied when the monitoring host is unreachable&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PBF rule is not applied when the monitoring host is unreachable. If no IP address is specified for monitoring,&amp;nbsp; then the next hop IP is monitored. When a PBF rule is configured with monitoring enabled,&amp;nbsp; the egress interface send keepalives to monitoring IP or next hop.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Does this mean that next rule will be applied (if there is a matching criteria) if first one is unreachable?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 11:46:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-monitor-target/m-p/598850#M119106</guid>
      <dc:creator>stefan.tomasevic</dc:creator>
      <dc:date>2024-09-26T11:46:23Z</dc:date>
    </item>
  </channel>
</rss>

