destination port in PBF

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

destination port in PBF

L2 Linker

Is there an option to define destination port in PBF. Now if a service is selected, PA applies PBF if source or destination has that port.

I am looking for a PBF which should match only if destination port is 80.

3 REPLIES 3

Cyber Elite
Cyber Elite

@ceapen01,

When you specify the service in a PBF that refers to the destination service (or port), not the source service/port. PBF wouldn't really be a lot of good in a lot of cases if the service object was applied to both source and destination. 

Cyber Elite
Cyber Elite

Hello there.

If you match only on port 80, you will be matching 1930 applications.  I need to ask the question.. WHY? 
PBF is used to supercede the routing table.  
Do you have more than one ISP?

What is the business justification, as we would probably NOT recommend this, as it will probably not work as expected.

Help the community: Like helpful comments and mark solutions

L2 Linker

Thank you @SCantwell_IM and @BPry 

 

@BPry I checked the session id details. PBF was being used even when source port is 80. Attached screenshot below.

port80.JPG

 

@SCantwell_IM i have added a scenario diagram below. PBF requirement is to route incoming web requests to 10.20.30.12 via INT 2. The DNAT for public IP has a source NAT with INT 2 interface IP, so that DC firewall sees source IP as PA FW INT 2.

scenario.JPG

 

 

 

 

  • 1670 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!