PBF Rule not being hit

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PBF Rule not being hit

L1 Bithead

I am experiencing an issue with one of our PAN devices, which is a PA-500 running OS 7.0.19. I have created a new PBF rule to forward traffic from a certain subnet to the inside interface of our edge router. I have several other rules pointing other subnets at the same interface which work fine. The PBF rule did not seem to work (yes it is commited). So, I ran the test from the CLI as below.

 

Zone/Interface: Zone2

Source Address: 10.80.80.0/24 (not real IP)

Destination Address: Any

Application: Any

Service: Any

Action: Forward

Egress Interface: Ethernet 1/2

Next hop: 12.12.12.1 (not real IP)

 

From CLI - test pbf-policy-match protocol 6 from Zone2 source 10.80.80.15 destination 8.8.8.8 destination-port 80

 

The results: "No rule matched"

 

Any idea what can cause this?

6 REPLIES 6

Cyber Elite
Cyber Elite

@WhiteKnight,

Just for fun, can you try setting the source as a single IP and then running your tests again? 

I was actually just trying that. I have a test box sitting on that subnet now. The rule is now set for the entire subnet as well as the single IP address. I didn't try the rule with the single IP and remove the subnet. I'll try that now.

 

Edit: I edited to rule to have the source as a single IP. It still results in "No rule matched"

@WhiteKnight,

And just to verify, have you looked for any validation errors with you having too many PBF entries? I know that our old 4000s back in the day could handle more than a few, so I doubt you are reaching the limit, but it might be worth checking. 

I always validate before commiting. When I do validate, there are no errors.

@WhiteKnight,

Hmm, that seems really odd. The only other reason I would suspect this to not work is if you were trying to utilize PBF for a globalprotect client. Outside of that you might want to open a ticket with TAC. 

Ok, thanks for the feedback. We do have current support but I figured it was worth asking here. Incase I'm completely overlooking something.

 

Thank you,

Matt

  • 5128 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!