- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-30-2019 05:27 AM
I am experiencing an issue with one of our PAN devices, which is a PA-500 running OS 7.0.19. I have created a new PBF rule to forward traffic from a certain subnet to the inside interface of our edge router. I have several other rules pointing other subnets at the same interface which work fine. The PBF rule did not seem to work (yes it is commited). So, I ran the test from the CLI as below.
Zone/Interface: Zone2
Source Address: 10.80.80.0/24 (not real IP)
Destination Address: Any
Application: Any
Service: Any
Action: Forward
Egress Interface: Ethernet 1/2
Next hop: 12.12.12.1 (not real IP)
From CLI - test pbf-policy-match protocol 6 from Zone2 source 10.80.80.15 destination 8.8.8.8 destination-port 80
The results: "No rule matched"
Any idea what can cause this?
07-30-2019 09:31 AM
Just for fun, can you try setting the source as a single IP and then running your tests again?
07-30-2019 10:17 AM - edited 07-30-2019 10:31 AM
I was actually just trying that. I have a test box sitting on that subnet now. The rule is now set for the entire subnet as well as the single IP address. I didn't try the rule with the single IP and remove the subnet. I'll try that now.
Edit: I edited to rule to have the source as a single IP. It still results in "No rule matched"
07-30-2019 10:35 AM
And just to verify, have you looked for any validation errors with you having too many PBF entries? I know that our old 4000s back in the day could handle more than a few, so I doubt you are reaching the limit, but it might be worth checking.
07-30-2019 10:38 AM
I always validate before commiting. When I do validate, there are no errors.
07-30-2019 10:42 AM
Hmm, that seems really odd. The only other reason I would suspect this to not work is if you were trying to utilize PBF for a globalprotect client. Outside of that you might want to open a ticket with TAC.
07-30-2019 10:46 AM
Ok, thanks for the feedback. We do have current support but I figured it was worth asking here. Incase I'm completely overlooking something.
Thank you,
Matt
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!