<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBF Dual ISP,  inbound NAT broke with spoofing protection enabled in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/435985#M96122</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34542"&gt;@drewdown&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you tell me why you are using PBF?&amp;nbsp; Most dual ISP designs can be handled by routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 22 Sep 2021 19:40:04 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2021-09-22T19:40:04Z</dc:date>
    <item>
      <title>PBF Dual ISP,  inbound NAT broke with spoofing protection enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/435222#M96049</link>
      <description>&lt;P&gt;Having an issue where we implemented PBF for dual ISPs on an HA pair that already had inbound NATs configured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we did this the inbound NATs broke and I found this article:&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClzeCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClzeCAC&lt;/A&gt;&amp;nbsp;which basically said to remove the interface from the PBF specific route which I did but that made no difference.&amp;nbsp; &amp;nbsp;In the end I had to disable 'Spoofed IP address' from the outside zone protection profile to get it working again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know why you can't have PBF, inbound NAT's and spoof protection enabled?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 13:13:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/435222#M96049</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-09-20T13:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Dual ISP,  inbound NAT broke with spoofing protection enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/435436#M96072</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Have you tried enforce symetric return option from pbf policy Forwarding section.&lt;/P&gt;&lt;P&gt;*Another idea, assign nat ip to a loopback interface than use it for nat.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 08:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/435436#M96072</guid>
      <dc:creator>upelister</dc:creator>
      <dc:date>2021-09-21T08:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Dual ISP,  inbound NAT broke with spoofing protection enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/435976#M96121</link>
      <description>&lt;P&gt;Do you mean enforce it on the PBF for the dual internet links?&amp;nbsp; PAN documentation is so bad and confusing I am not even sure who they got managing it, a trained monkey?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 19:15:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/435976#M96121</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-09-22T19:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Dual ISP,  inbound NAT broke with spoofing protection enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/435985#M96122</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34542"&gt;@drewdown&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you tell me why you are using PBF?&amp;nbsp; Most dual ISP designs can be handled by routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 19:40:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/435985#M96122</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-22T19:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Dual ISP,  inbound NAT broke with spoofing protection enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/436188#M96238</link>
      <description>&lt;P&gt;Pray tell how its handled by routing without running BGP between our multitude of carriers?&amp;nbsp; And what is PBF if not routing?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Besides here is one of many PA articles outlining how to configure DUAL ISPs with failover using PBF:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/policy-based-forwarding/use-case-pbf-for-outbound-access-with-dual-isps" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/policy-based-forwarding/use-case-pbf-for-outbound-access-with-dual-isps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 16:28:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/436188#M96238</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-09-23T16:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Dual ISP,  inbound NAT broke with spoofing protection enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/436192#M96240</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34542"&gt;@drewdown&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ahh!&amp;nbsp; I see.&amp;nbsp; You are using PBF because the article which you posted said to use it.&amp;nbsp; My bad.&amp;nbsp; I use this method with my customers -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO&lt;/A&gt;.&amp;nbsp; It works well.&amp;nbsp; It uses route metrics for forwarding and not PBF.&amp;nbsp; It's more straightforward.&amp;nbsp; I am curious if removing PBF may remove the NAT issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While PBF is policy routing, I prefer a route table lookup.&amp;nbsp; That's what I meant by routing.&amp;nbsp; The nice thing about using the route table is that you can also use both ISPs if you want.&amp;nbsp; You would need to enable ECMP in your VR.&amp;nbsp; I would check the Symmetric Return box.&amp;nbsp; I had one customer where load balancing broke voice, but changing the ECMP method to IP Hash fixed the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regard to path monitoring, I like to use 2 Internet IP addresses so that one down host doesn't take down the circuit.&amp;nbsp; I ran into one customer (not my setup) that was monitoring 8.8.8.8 for HA path monitoring, and the host went down causing a firewall failover!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 16:55:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/436192#M96240</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-23T16:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: PBF Dual ISP,  inbound NAT broke with spoofing protection enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/436195#M96241</link>
      <description>&lt;P&gt;Hell yeah brother!&amp;nbsp; Another PA article yet giving another way to skin a cat.&amp;nbsp; I will take a look and see if it works better because I absolutely hate PBF with a passion and all the nuances (breaking) that comes along with it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess this just goes back to PA articles and so many offering so many different solutions.&amp;nbsp; I mean I do it one way and you do it a completely different way but if I google PA dual ISPs the first link is using PBF.&amp;nbsp; &amp;nbsp;Also PBF monitors the link as well to an external IP it just requires that you have all the networks defined that you want to be applied to that PBF.&amp;nbsp; It then breaks inbound NAT as you can see and causes issue with VPN traffic hairpinning to the internet and to other VPN tunnels.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 17:01:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-dual-isp-inbound-nat-broke-with-spoofing-protection-enabled/m-p/436195#M96241</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-09-23T17:01:09Z</dc:date>
    </item>
  </channel>
</rss>

