Issue with PBF Symmetric Return

Reply
Highlighted
L1 Bithead

Issue with PBF Symmetric Return

We are running PanOS-10.0.2 on our PA-220 and we are having an issue with a PBF rule which seems to be denied even though it should match the traffic.

 

The setup:

2 WAN interfaces:

  • Primary = PPPoE interface on ETH 1/5. Route is added to router when PPPoE is online with metric 10
  • Secondary = "Normal" interface on ae1.100. Static route is in router with metric 20

For this example, I will use the IP's 1.2.3.4 for Primary and 5.6.7.8 for secondary

 

For both interfaces ping is allowed and there is a PBF rule added with Enforce Symmetric Return:

2020-11-02 15_06_01-Window.png

 

Primary WAN is working fine and failover is going as expected as soon as the PPPoE goes offline. Only issue is when both WAN are online, a ping to the secondary WAN is not working.

 

What happens is:

  • Ping from random WAN IP to 5.6.7.8
  • No response is received
  • Packet trace shows that the reply is sent over eth1/5 with 5.6.7.8 as source IP

Because of the PBF rule I would expect the reply to use the same interface, but instead it seems to ignore this and use the route with lowest metric.

 

Anyone around who has an idea why this is not working?

Highlighted
Cyber Elite

@mvrijsten,

Is the interface that you are attempting to ping the interface of the secondary WAN connection on the firewall itself? The PBF lookup is skipped for anything going from/to the firewall itself. 

Highlighted
L1 Bithead

@BPry ,

Yes that is correct. I am trying to ping the WAN IP.

 

But as a check, I just also created a Dest. Nat rule to a internal webserver on this IP and that also does not work. Same issue is happening, so it does not seem to be the issue that it is the WAN IP I am trying to ping. Otherwise it should work with the NAT rule right?

Highlighted
Cyber Elite

@mvrijsten 

 

As my esteemed CyberElite member @BPry  stated, you CANNOT use the WAN IP for your testing.

If you had additional public IPs available, you can do testing.

 

But.. PBF will not work if you do any testing that involves the use of the FWs public IP interfaces.

 

Thanks

Help the community: Like helpful comments and mark solutions
Highlighted
L1 Bithead

Thank you, I think I understand now.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!