Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Does PBF rule works for traffic originating from Global Protect Client

L3 Networker

Hi All,

 

We have two Global Protect portals/Gateways configured on each firewall ISP 1(Eth 1/1) and ISP 2(Eth 1/2) interfaces.

 

We had enabled ECMP on the firewall with max path 2 and configured ISP 1 and ISP 2 as default routes.

 

When an user is connected to GP configured on ISP 2 interface and trying to access internet the traffic from GP client is routed through ISP 1 interface.

 

As ECMP is configured this is an expected behaviour. 

 

Can we use an PBF rule to route the traffic originating from end user GP Client to go through an particular interface.

 

In the below article it is mentioned that Global protect traffic cannot be routed using PBF policy. Is it also applicable for the traffic originating from GP client end user system.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbDCAS#:~:text=PBF%20does...

 

Thanks in advance.

 

 

Who rated this post