PBF: unused rules

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PBF: unused rules

L4 Transporter

Hey all,

I am using multiple PBF rules and am 100% sure that nearly half of them have been hit after the last reboot. However, when I select "Highlight unused rules", it highlights all my rules..

Anyone else seeing this?

Kind regards,

Bob

5 REPLIES 5

L5 Sessionator

Hello Bob,

The best way to make sure your PBF rules are hit in GUI is to pull down another column 'Egress IF' in traffic logs and verify the traffic is going out on the interface you specified in pbf policy.

Other way to check is through CLI command.

>show pbf rule all

Make sure all rules are active.

>test pbf-policy-match source <ip-address> destination <ip-address> protocol <number> destination-port <number>.

Regards,

Hari Yadavalli

Yes, I know, that's how I was 100% sure that the rules were being hit.

But it made no sense to me that they were highlighted as unused and was wondering if this is a bug or not.

Kind regards,

Bob

L5 Sessionator

Hello Bob,

There was a known issue related to highlight unused rules and fixed in OS version 4.1.8.

Can you confirm the OS version?

Regards,

Hari Yadavalli

Hey,

PANOS 5.0.3

Kind regards

L4 Transporter

Hello,

Have you tried to run the below command and see the results,

"show running rule-use rule-base pbf type unused vsys vsys1"

Would the results look different from the GUI. Pls share.

Thanks

  • 3333 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!