<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN routing IPv6 traffic to UnTrust with default route pointing elsewhere in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423407#M94159</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I figured it out part of it....stupid PBF.&amp;nbsp; So I had PBF for IPv4 internet redundancy and if I added the source IPv6 network to it the traffic went in the right direction from Trust &amp;gt; Lab but not the other.&amp;nbsp; And since I don't have IPv6 on the egress interface I had to create a no PBF for the IPv6 traffic and set it to Not forward.&amp;nbsp; Once I did that it started working in both directions but not back from the internet.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jul 2021 15:38:42 GMT</pubDate>
    <dc:creator>drewdown</dc:creator>
    <dc:date>2021-07-30T15:38:42Z</dc:date>
    <item>
      <title>PAN routing IPv6 traffic to UnTrust with default route pointing elsewhere</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423226#M94139</link>
      <description>&lt;P&gt;I have a PAN on the internet with only IPv4.&amp;nbsp; I have an ASA dual stacked that I want to send IPv6 traffic from hosts connected behind the PAN to the ASA via the LAN.&amp;nbsp; All the interfaces on the PAN in the path have IPv6 configured. However, when the pan receives IPv6 packets that need to route it simply sends it out the UnTrust zone vs the Trust zone where my default and other static IPv6 routes reside.&amp;nbsp; &amp;nbsp;Note IPv4 is working fine and I can ping the Lab interfaces from the host behind the PAN and so forth, its just any IPv6 traffic that needs to be routed past (or through) these PANs that gets punted to the UnTrust zone and I can't figure out why.&amp;nbsp; &amp;nbsp; Its like its not even looking at the IPv6 route table.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next hop of IPv6 edge gateway ASA:&amp;nbsp;2403:8600:80CF:E100:2000::3&lt;/P&gt;&lt;P&gt;PAN Trust interface:&amp;nbsp;&amp;nbsp;2403:8600:80CF:E100:2000::5/68&lt;/P&gt;&lt;P&gt;PAN Lab interface:&amp;nbsp;2403:8600:80cf:e101:2000::1/68&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN Lab next hop:&amp;nbsp;2403:8600:80cf:e101:2000::2/68&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN Lab CIDR:&amp;nbsp;2403:8600:80cf:e10c:3780::/73&lt;/P&gt;&lt;P&gt;PAN Lab host:&amp;nbsp;2403:8600:80CF:E10C:3710::10&lt;/P&gt;&lt;P&gt;Eth1/1 is my Trust interface and Eth1/15 is my Lab interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPv6 route table is below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_1-1627585916395.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35331i4D02D86911625914/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="drewdown_1-1627585916395.png" alt="drewdown_1-1627585916395.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have policies allowing all the traffic but it seems like anything it doesn't have a specific IPv6 route for it sends it to the Untrust zone even though the default route is pointing out eth1/1 to&amp;nbsp;2403:8600:80CF:E100:2000::3.&amp;nbsp; Why would the PAN still try to send the traffic out the UnTrust interface at this point?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the logs below you can see a ping from the ASA (.3) gets punted to UnTrust.&amp;nbsp; But a ping from the PAN itself (.1) routes within that zone without issue all to the same host&amp;nbsp;2403:8600:80CF:E10C:3710::10.&amp;nbsp; No matter what I do I cannot get the PAN to route all IPv6 traffic to the trust or lab zones, none of it should be going to untrust as there is no IPv6 configured on that zone/interface.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_0-1627587532904.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35335i804DA8B1B7B4AE56/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="drewdown_0-1627587532904.png" alt="drewdown_0-1627587532904.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 20:38:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423226#M94139</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-07-29T20:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: PAN routing IPv6 traffic to UnTrust with default route pointing elsewhere</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423307#M94148</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34542"&gt;@drewdown&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Have you tried looking at the route table directly on the CLI to ensure that it isn't installing the route incorrectly or learning it from your interface undesirably?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 03:03:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423307#M94148</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-07-30T03:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: PAN routing IPv6 traffic to UnTrust with default route pointing elsewhere</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423407#M94159</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I figured it out part of it....stupid PBF.&amp;nbsp; So I had PBF for IPv4 internet redundancy and if I added the source IPv6 network to it the traffic went in the right direction from Trust &amp;gt; Lab but not the other.&amp;nbsp; And since I don't have IPv6 on the egress interface I had to create a no PBF for the IPv6 traffic and set it to Not forward.&amp;nbsp; Once I did that it started working in both directions but not back from the internet.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 15:38:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423407#M94159</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-07-30T15:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: PAN routing IPv6 traffic to UnTrust with default route pointing elsewhere</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423426#M94160</link>
      <description>&lt;P&gt;So now I have&amp;nbsp; similar issue with IPv6 traffics return path from the internet.&amp;nbsp; &amp;nbsp;So the return or inbound IPv6 traffic comes across the Trust interface and should all be routed to the LAB but it is routing that traffic to UnTrust.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the no IPv6 PBF:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_1-1627659474064.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35356i4338647E8423765D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="drewdown_1-1627659474064.png" alt="drewdown_1-1627659474064.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet &amp;gt; Trust &amp;gt; Lab but its going Internet &amp;gt; Trust &amp;gt; UnTrust so something not right with my PBF but not clear on what:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_2-1627659584727.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35357i8A6E6793BA6FAAD9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="drewdown_2-1627659584727.png" alt="drewdown_2-1627659584727.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 15:40:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423426#M94160</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-07-30T15:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: PAN routing IPv6 traffic to UnTrust with default route pointing elsewhere</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423430#M94161</link>
      <description>&lt;P&gt;so if you have PBF for internet redundancy and your IPv6 gateway is via some other zone/interface outside of your untrust then you need 2 x PBF rules in both directions for that IPv6 traffic.&amp;nbsp; Simply having one or the other will break it in either direction.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_4-1627660138166.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35359i2F75C98CE6612C0E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="drewdown_4-1627660138166.png" alt="drewdown_4-1627660138166.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 16:12:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-routing-ipv6-traffic-to-untrust-with-default-route-pointing/m-p/423430#M94161</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-08-24T16:12:56Z</dc:date>
    </item>
  </channel>
</rss>

