- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-02-2020 06:15 AM
We are running PanOS-10.0.2 on our PA-220 and we are having an issue with a PBF rule which seems to be denied even though it should match the traffic.
The setup:
2 WAN interfaces:
For this example, I will use the IP's 1.2.3.4 for Primary and 5.6.7.8 for secondary
For both interfaces ping is allowed and there is a PBF rule added with Enforce Symmetric Return:
Primary WAN is working fine and failover is going as expected as soon as the PPPoE goes offline. Only issue is when both WAN are online, a ping to the secondary WAN is not working.
What happens is:
Because of the PBF rule I would expect the reply to use the same interface, but instead it seems to ignore this and use the route with lowest metric.
Anyone around who has an idea why this is not working?
11-02-2020 07:09 PM
Is the interface that you are attempting to ping the interface of the secondary WAN connection on the firewall itself? The PBF lookup is skipped for anything going from/to the firewall itself.
11-02-2020 10:53 PM
@BPry ,
Yes that is correct. I am trying to ping the WAN IP.
But as a check, I just also created a Dest. Nat rule to a internal webserver on this IP and that also does not work. Same issue is happening, so it does not seem to be the issue that it is the WAN IP I am trying to ping. Otherwise it should work with the NAT rule right?
11-03-2020 05:41 AM
As my esteemed CyberElite member @BPry stated, you CANNOT use the WAN IP for your testing.
If you had additional public IPs available, you can do testing.
But.. PBF will not work if you do any testing that involves the use of the FWs public IP interfaces.
Thanks
11-04-2020 05:38 AM
Thank you, I think I understand now.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!