I am experiencing an issue with one of our PAN devices, which is a PA-500 running OS 7.0.19. I have created a new PBF rule to forward traffic from a certain subnet to the inside interface of our edge router. I have several other rules pointing other subnets at the same interface which work fine. The PBF rule did not seem to work (yes it is commited). So, I ran the test from the CLI as below.
Source Address: 10.80.80.0/24 (not real IP)
Destination Address: Any
Egress Interface: Ethernet 1/2
Next hop: 18.104.22.168 (not real IP)
From CLI - test pbf-policy-match protocol 6 from Zone2 source 10.80.80.15 destination 22.214.171.124 destination-port 80
The results: "No rule matched"
Any idea what can cause this?
I was actually just trying that. I have a test box sitting on that subnet now. The rule is now set for the entire subnet as well as the single IP address. I didn't try the rule with the single IP and remove the subnet. I'll try that now.
Edit: I edited to rule to have the source as a single IP. It still results in "No rule matched"
And just to verify, have you looked for any validation errors with you having too many PBF entries? I know that our old 4000s back in the day could handle more than a few, so I doubt you are reaching the limit, but it might be worth checking.
Hmm, that seems really odd. The only other reason I would suspect this to not work is if you were trying to utilize PBF for a globalprotect client. Outside of that you might want to open a ticket with TAC.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!