We are running PanOS-10.0.2 on our PA-220 and we are having an issue with a PBF rule which seems to be denied even though it should match the traffic.
2 WAN interfaces:
For this example, I will use the IP's 126.96.36.199 for Primary and 188.8.131.52 for secondary
For both interfaces ping is allowed and there is a PBF rule added with Enforce Symmetric Return:
Primary WAN is working fine and failover is going as expected as soon as the PPPoE goes offline. Only issue is when both WAN are online, a ping to the secondary WAN is not working.
What happens is:
Because of the PBF rule I would expect the reply to use the same interface, but instead it seems to ignore this and use the route with lowest metric.
Anyone around who has an idea why this is not working?
Is the interface that you are attempting to ping the interface of the secondary WAN connection on the firewall itself? The PBF lookup is skipped for anything going from/to the firewall itself.
Yes that is correct. I am trying to ping the WAN IP.
But as a check, I just also created a Dest. Nat rule to a internal webserver on this IP and that also does not work. Same issue is happening, so it does not seem to be the issue that it is the WAN IP I am trying to ping. Otherwise it should work with the NAT rule right?
As my esteemed CyberElite member @BPry stated, you CANNOT use the WAN IP for your testing.
If you had additional public IPs available, you can do testing.
But.. PBF will not work if you do any testing that involves the use of the FWs public IP interfaces.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!