- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-01-2022 04:16 AM
Is there an option to define destination port in PBF. Now if a service is selected, PA applies PBF if source or destination has that port.
I am looking for a PBF which should match only if destination port is 80.
02-01-2022 06:22 PM
When you specify the service in a PBF that refers to the destination service (or port), not the source service/port. PBF wouldn't really be a lot of good in a lot of cases if the service object was applied to both source and destination.
02-01-2022 06:22 PM
Hello there.
If you match only on port 80, you will be matching 1930 applications. I need to ask the question.. WHY?
PBF is used to supercede the routing table.
Do you have more than one ISP?
What is the business justification, as we would probably NOT recommend this, as it will probably not work as expected.
02-01-2022 09:30 PM
Thank you @S.Cantwell and @BPry
@BPry I checked the session id details. PBF was being used even when source port is 80. Attached screenshot below.
@S.Cantwell i have added a scenario diagram below. PBF requirement is to route incoming web requests to 10.20.30.12 via INT 2. The DNAT for public IP has a source NAT with INT 2 interface IP, so that DC firewall sees source IP as PA FW INT 2.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!