<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Policy-based forwarding be used for routing the firewall connection for updates? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-policy-based-forwarding-be-used-for-routing-the-firewall/m-p/377892#M89410</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136122"&gt;@FrankMurray&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF will not work for the traffic which is originating from PA firewall interfaces. It will get used only for the systems which are behind firewall. So when traffic is originating from the firewall, it will use routing table to check routes for the desired destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jan 2021 06:02:21 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2021-01-05T06:02:21Z</dc:date>
    <item>
      <title>Can Policy-based forwarding be used for routing the firewall connection for updates?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-policy-based-forwarding-be-used-for-routing-the-firewall/m-p/377866#M89408</link>
      <description>&lt;P&gt;We've got a firewall that doesn't have a management interface connection.&amp;nbsp; The default route for the firewall is configured across a tunnel interface. The service route has been been configured to use the outside interface- there's no option to use the tunnel interface.&lt;/P&gt;&lt;P&gt;I'm trying to get Policy-based forwarding working so traffic sourced from the firewall's outside interface has a 0.0.0.0/0 route to the next-hop router.&amp;nbsp; But it's not working-&amp;nbsp; can't get dynamic updates. Can't download software.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 02:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-policy-based-forwarding-be-used-for-routing-the-firewall/m-p/377866#M89408</guid>
      <dc:creator>FrankMurray</dc:creator>
      <dc:date>2021-01-05T02:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can Policy-based forwarding be used for routing the firewall connection for updates?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-policy-based-forwarding-be-used-for-routing-the-firewall/m-p/377892#M89410</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136122"&gt;@FrankMurray&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF will not work for the traffic which is originating from PA firewall interfaces. It will get used only for the systems which are behind firewall. So when traffic is originating from the firewall, it will use routing table to check routes for the desired destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 06:02:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-policy-based-forwarding-be-used-for-routing-the-firewall/m-p/377892#M89410</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-01-05T06:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can Policy-based forwarding be used for routing the firewall connection for updates?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-policy-based-forwarding-be-used-for-routing-the-firewall/m-p/377967#M89421</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136122"&gt;@FrankMurray&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is one of the reason I really hate setup that requires default route pointing to VPN tunnel. I would suggest you do to the following, which unfortunately will require a massive change:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Create two separate virtual-rotuers (vr).&lt;/P&gt;&lt;P&gt;2. Assing your outside/public fw interface to vr1 and configure the default route via the public interface&lt;/P&gt;&lt;P&gt;3. Assing your lan/internal fw interface to vr2.&lt;/P&gt;&lt;P&gt;4. Configure your IPsec tunnel to use your public/outside interface for local peer IP, &lt;STRONG&gt;but &lt;/STRONG&gt;assing the tunnel interface to vr2&lt;/P&gt;&lt;P&gt;5. Configure the default route for vr2 to the tunnel interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will allow you to have default route for the internal resource pointing to the tunnel, while the fw still have default route pointing to the next-hop via the outside interface. After that is should be enough to set the service route to use the public interface which will take the default route from vr1 of to public internet and not vpn.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 14:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-policy-based-forwarding-be-used-for-routing-the-firewall/m-p/377967#M89421</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-01-05T14:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can Policy-based forwarding be used for routing the firewall connection for updates?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-policy-based-forwarding-be-used-for-routing-the-firewall/m-p/529103#M109231</link>
      <description>&lt;P&gt;So that's why my lab environment to test 2 ISP connection never worked&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 03:58:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-policy-based-forwarding-be-used-for-routing-the-firewall/m-p/529103#M109231</guid>
      <dc:creator>Braulio.Pineda</dc:creator>
      <dc:date>2023-01-30T03:58:19Z</dc:date>
    </item>
  </channel>
</rss>

