PBF Rule not being hit

Reply
Highlighted
L1 Bithead

PBF Rule not being hit

I am experiencing an issue with one of our PAN devices, which is a PA-500 running OS 7.0.19. I have created a new PBF rule to forward traffic from a certain subnet to the inside interface of our edge router. I have several other rules pointing other subnets at the same interface which work fine. The PBF rule did not seem to work (yes it is commited). So, I ran the test from the CLI as below.

 

Zone/Interface: Zone2

Source Address: 10.80.80.0/24 (not real IP)

Destination Address: Any

Application: Any

Service: Any

Action: Forward

Egress Interface: Ethernet 1/2

Next hop: 12.12.12.1 (not real IP)

 

From CLI - test pbf-policy-match protocol 6 from Zone2 source 10.80.80.15 destination 8.8.8.8 destination-port 80

 

The results: "No rule matched"

 

Any idea what can cause this?

Tags (3)
Highlighted
Cyber Elite

@WhiteKnight,

Just for fun, can you try setting the source as a single IP and then running your tests again? 

Highlighted
L1 Bithead

I was actually just trying that. I have a test box sitting on that subnet now. The rule is now set for the entire subnet as well as the single IP address. I didn't try the rule with the single IP and remove the subnet. I'll try that now.

 

Edit: I edited to rule to have the source as a single IP. It still results in "No rule matched"

Highlighted
Cyber Elite

@WhiteKnight,

And just to verify, have you looked for any validation errors with you having too many PBF entries? I know that our old 4000s back in the day could handle more than a few, so I doubt you are reaching the limit, but it might be worth checking. 

Highlighted
L1 Bithead

I always validate before commiting. When I do validate, there are no errors.

Highlighted
Cyber Elite

@WhiteKnight,

Hmm, that seems really odd. The only other reason I would suspect this to not work is if you were trying to utilize PBF for a globalprotect client. Outside of that you might want to open a ticket with TAC. 

Highlighted
L1 Bithead

Ok, thanks for the feedback. We do have current support but I figured it was worth asking here. Incase I'm completely overlooking something.

 

Thank you,

Matt

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!