<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Policy base routing for internal trafique in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-base-routing-for-internal-trafique/m-p/438474#M97539</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36765i4120E35BBA2CFD00/image-size/large?v=v2&amp;amp;px=999" border="0" alt="Aperçu de l'image de couverture" title="Capture.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;Hello everyone,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;I have two ISPs wan1 and wan2, for lan 1 it must go out through wan1 and lan2 through wan2.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;in the event of a problem with one of the wans, the associated lan will have to exit through the other wan temporarily.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;To do this, configure them two default routes with different metrics:&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;0.0.0.0/0 =wan 1 with metric of 10&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;0.0.0.0/0 = wan 2 with metric of 15&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;and in policy base routing:&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;Lan2 = wan2 until everything works the problem is that I cannot put monitoring on the PBR and when I take the address of the E1 / 2 port in cli and I ping 8.8.8.8 it does not take the PBR in&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;consideration and it is the same for the moritor generated by the PBR while I have correctly specified the address of the interface and made several tests, also the PBR is tested and works correctly.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;My question is: what are the steps on which traffic generated by the interface will go through, and if you have a solution, thank you very much.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Oct 2021 14:58:49 GMT</pubDate>
    <dc:creator>Abdelfettah</dc:creator>
    <dc:date>2021-10-04T14:58:49Z</dc:date>
    <item>
      <title>Policy base routing for internal trafique</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-base-routing-for-internal-trafique/m-p/438474#M97539</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36765i4120E35BBA2CFD00/image-size/large?v=v2&amp;amp;px=999" border="0" alt="Aperçu de l'image de couverture" title="Capture.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;Hello everyone,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;I have two ISPs wan1 and wan2, for lan 1 it must go out through wan1 and lan2 through wan2.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;in the event of a problem with one of the wans, the associated lan will have to exit through the other wan temporarily.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;To do this, configure them two default routes with different metrics:&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;0.0.0.0/0 =wan 1 with metric of 10&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;0.0.0.0/0 = wan 2 with metric of 15&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;and in policy base routing:&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;Lan2 = wan2 until everything works the problem is that I cannot put monitoring on the PBR and when I take the address of the E1 / 2 port in cli and I ping 8.8.8.8 it does not take the PBR in&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;consideration and it is the same for the moritor generated by the PBR while I have correctly specified the address of the interface and made several tests, also the PBR is tested and works correctly.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;My question is: what are the steps on which traffic generated by the interface will go through, and if you have a solution, thank you very much.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 14:58:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-base-routing-for-internal-trafique/m-p/438474#M97539</guid>
      <dc:creator>Abdelfettah</dc:creator>
      <dc:date>2021-10-04T14:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Policy base routing for internal trafique</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-base-routing-for-internal-trafique/m-p/438519#M97540</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Policy based routing takes effect before the virtual router has a chance to do any routing on the traffic. For the monitor, choose the IP address of the ISP gateway. In your virtual router, put in a static route for that gateway as a /32 address out the proper interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;Static Router WAN1 Gateway:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1633367351630.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36771i6C4DB7AEB75DFAA8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1633367351630.png" alt="OtakarKlier_0-1633367351630.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This forces all the traffic destined for the WAN1 gateway out that interface. Then use that WAN1 gateway IP for your monitor IP in the PBF. This way if that IP is unreachable, PBF policy will disable its self. Since its a /32 address, general routing priciples tell the system that its a more specific route than the default so the default route will never get used to get to the WAN1 IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Similar for WAN2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 17:11:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-base-routing-for-internal-trafique/m-p/438519#M97540</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-10-04T17:11:15Z</dc:date>
    </item>
  </channel>
</rss>

