Hi @drewdown , Ahh! I see. You are using PBF because the article which you posted said to use it. My bad. I use this method with my customers -> https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO. It works well. It uses route metrics for forwarding and not PBF. It's more straightforward. I am curious if removing PBF may remove the NAT issue. While PBF is policy routing, I prefer a route table lookup. That's what I meant by routing. The nice thing about using the route table is that you can also use both ISPs if you want. You would need to enable ECMP in your VR. I would check the Symmetric Return box. I had one customer where load balancing broke voice, but changing the ECMP method to IP Hash fixed the issue. With regard to path monitoring, I like to use 2 Internet IP addresses so that one down host doesn't take down the circuit. I ran into one customer (not my setup) that was monitoring 8.8.8.8 for HA path monitoring, and the host went down causing a firewall failover! Thanks, Tom
... View more