<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Any to Specific VPN Breakout in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340897#M85531</link>
    <description>&lt;P&gt;I can only applaud that &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jul 2020 17:13:08 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2020-07-27T17:13:08Z</dc:date>
    <item>
      <title>Any to Specific VPN Breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340575#M85470</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm having an issue. I have a catchall VPN tunnel on my Palo Alto that sends all of my traffic to a company called Zscaler. They are a cloud security company that acts as a proxy to intercept our traffic and check it before it goes out to the internet and vice-versa.&amp;nbsp; However, sometimes certain exchanges don't play nice with Zscaler, such as our cloud hosted VOIP traffic, and as such, I need to configure a NAT breakout to route traffic destinated to our cloud VOIP provider's PBX away from that VPN tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am finding is that NAT breakouts on the Palo work IF they are "Specific-to-Any," but "Any-to-Specific" VPN breakouts have no effect, and the traffic still gets sucked into Zscaler. Example below.&amp;nbsp; ANy help is appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dromanelli_0-1595621800306.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27011i1C0647079BDAB4EC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dromanelli_0-1595621800306.png" alt="dromanelli_0-1595621800306.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2020 20:16:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340575#M85470</guid>
      <dc:creator>dromanelli</dc:creator>
      <dc:date>2020-07-24T20:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: Any to Specific VPN Breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340732#M85486</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/141381"&gt;@dromanelli&lt;/a&gt;NAT is subordinate to routing, so if you need to route things away from the VPN tunnel, you should probably look into policy based forwarding or a static route with a lower metric than what you are pushing into the ZScaler tunnel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;only after routing is determined will NAT be applied&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jul 2020 20:32:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340732#M85486</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-07-26T20:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Any to Specific VPN Breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340839#M85513</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&amp;nbsp; So I actually tried the PBF first before coming here and unfortunately that broke other traffic, so I reverted it.&amp;nbsp; I am willing to look into the static routes.&amp;nbsp; Below is my route table:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dromanelli_0-1595856235247.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27045iC985584470591F6E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dromanelli_0-1595856235247.png" alt="dromanelli_0-1595856235247.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So right now I just have a single outbound route to my ISP gateway out Ethernet1/1. The Zscaler tunnels are not explicitly called in my route table. It just takes the default route and gets dumped into the VPN. The interfaces for those are tunnel.1 (primary) and tunnel.2 (backup). Is there a way I can reconfigure these routes to add a Zscaler default route and a general internet default route?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 13:29:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340839#M85513</guid>
      <dc:creator>dromanelli</dc:creator>
      <dc:date>2020-07-27T13:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Any to Specific VPN Breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340844#M85515</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/141381"&gt;@dromanelli&lt;/a&gt;&amp;nbsp; then you probably have a policy based forwarding rule for zscaler; traffic needs direction to go into a tunnel, either by a static route or a pbf policy. it can't just be dropped in a tunnel without one of both methods&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to bypass the zscaler pbf, you need to add an exception rule above it, something along the lines of the picture below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-07-27_15-45-39.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27047i287458C0B0065A71/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020-07-27_15-45-39.png" alt="2020-07-27_15-45-39.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 13:47:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340844#M85515</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-07-27T13:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: Any to Specific VPN Breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340849#M85518</link>
      <description>&lt;P&gt;I do, yes.&amp;nbsp; See below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dromanelli_0-1595858301303.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27048iFABAB23614721F1A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dromanelli_0-1595858301303.png" alt="dromanelli_0-1595858301303.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What I tried to do before posting was place the following, but it ended up breaking traffic, so I disabled it. After looking at your screenshot, I think I see why. I have the action set to Forward instead of no-pbf:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dromanelli_1-1595858444082.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27049i567A91BCF27EA0BE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dromanelli_1-1595858444082.png" alt="dromanelli_1-1595858444082.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So in theory, if I change that to no-pbf, this should accomplish what I need right?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 14:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340849#M85518</guid>
      <dc:creator>dromanelli</dc:creator>
      <dc:date>2020-07-27T14:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Any to Specific VPN Breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340850#M85519</link>
      <description>&lt;P&gt;correct&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can set that additional rule to no-pbf (make sure it is ABOVE the zscaler rule) which will bypass the zcaler policy&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;you see those strikethrough subnets in the zscaler rule source, those are essentially also overrides&lt;/P&gt;&lt;P&gt;it sets the rule to 'forward everything THAT ARE NOT these subnets'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could be helpful too&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 14:19:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340850#M85519</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-07-27T14:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: Any to Specific VPN Breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340860#M85521</link>
      <description>&lt;P&gt;Thanks very much.&amp;nbsp; When does your book come out by the way? I'd like to get a hard cover copy.&amp;nbsp; Is that a good book for Palo beginners? I'm Cisco-seasoned but Palo Green.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 14:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340860#M85521</guid>
      <dc:creator>dromanelli</dc:creator>
      <dc:date>2020-07-27T14:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Any to Specific VPN Breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340863#M85523</link>
      <description>&lt;P&gt;It aims at all levels of expertise: get you started quickly, walk you through all sorts of config and add tips, tricks and 'tribal knowledge' I acquired over the years ,&lt;/P&gt;&lt;P&gt;it launches with &lt;A title="Mastering Palo Alto Networks" href="https://www.packtpub.com/eu/cloud-networking/mastering-palo-alto-networks" target="_blank" rel="noopener"&gt;my publisher&lt;/A&gt; on august 7 and &lt;A title="Mastering Palo Alto Networks" href="https://www.amazon.com/Mastering-Palo-Alto-Networks-industry-leading/dp/1789956374" target="_blank" rel="noopener"&gt;amazon&lt;/A&gt; on september 9 &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 15:15:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340863#M85523</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-07-27T15:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Any to Specific VPN Breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340893#M85530</link>
      <description>&lt;P&gt;Great. I'll be buying one.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 17:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340893#M85530</guid>
      <dc:creator>dromanelli</dc:creator>
      <dc:date>2020-07-27T17:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Any to Specific VPN Breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340897#M85531</link>
      <description>&lt;P&gt;I can only applaud that &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 17:13:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-to-specific-vpn-breakout/m-p/340897#M85531</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-07-27T17:13:08Z</dc:date>
    </item>
  </channel>
</rss>

