<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW routing packets to internet vs internal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fw-routing-packets-to-internet-vs-internal/m-p/393524#M91022</link>
    <description>&lt;P&gt;I figured this out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Co-worker had enabled PBR for ISP failover but did not include the cloud ip ranges in the destination IP ranges on that PBR rule so it was routing all of that out to the internet vs the core.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Mar 2021 18:34:52 GMT</pubDate>
    <dc:creator>drewdown</dc:creator>
    <dc:date>2021-03-24T18:34:52Z</dc:date>
    <item>
      <title>FW routing packets to internet vs internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fw-routing-packets-to-internet-vs-internal/m-p/393508#M91020</link>
      <description>&lt;P&gt;I have a weird issue with a LAB interface/zone that when packets to a cloud IP that is reachable via the core it routes it to the internet vs the core.&amp;nbsp; &amp;nbsp;All other traffic is routed correctly but not this and I can't seem to figure out why.&amp;nbsp; 10.100.2.1 is my core, 10.100.99.1 is the lab interface on the PAN which is part of VR1 (only virtual router configured).&amp;nbsp; You can see in the trace it goes from the lab interface to the WAN/outside rather than the core even with a route configured.&amp;nbsp; &amp;nbsp;If I ping 172.24.4.76 from the FW using 10.100.99.1 as the source IP it works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be causing this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;src: 10.49.1.62&lt;/P&gt;&lt;P&gt;dst: 172.24.4.76&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;VIRTUAL ROUTER: VR1 (id 1)
  ==========
destination                                 nexthop                                 metric flags      age   interface
  next-AS
172.24.4.0/24                               10.100.2.1                              10     A S              ae2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;traceroute 172.24.4.76
traceroute to 172.24.4.76 (172.24.4.76), 30 hops max, 40 byte packets
 1  10.49.1.1 (10.49.1.1)  0.950 ms  0.536 ms  0.565 ms
 2  10.255.49.1 (10.255.49.1)  0.407 ms  0.783 ms  2.171 ms
 3  10.100.99.1 (10.100.99.1)  0.542 ms  3.915 ms  2.626 ms
 4  12.13.99.161 (12.13.99.161)  1.371 ms  3.335 ms  0.648 ms&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 17:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fw-routing-packets-to-internet-vs-internal/m-p/393508#M91020</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-03-24T17:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: FW routing packets to internet vs internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fw-routing-packets-to-internet-vs-internal/m-p/393524#M91022</link>
      <description>&lt;P&gt;I figured this out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Co-worker had enabled PBR for ISP failover but did not include the cloud ip ranges in the destination IP ranges on that PBR rule so it was routing all of that out to the internet vs the core.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 18:34:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fw-routing-packets-to-internet-vs-internal/m-p/393524#M91022</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-03-24T18:34:52Z</dc:date>
    </item>
  </channel>
</rss>

