Create a Policy-Based Forwarding Rule
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
- Cloud Management of NGFWs
- PAN-OS 10.0 (EoL)
- PAN-OS 10.1
- PAN-OS 10.2
- PAN-OS 11.0
- PAN-OS 11.1 & Later
- PAN-OS 9.1 (EoL)
-
- PAN-OS 10.1
- PAN-OS 10.2
- PAN-OS 11.0
- PAN-OS 11.1 & Later
-
-
-
- Cloud Management and AIOps for NGFW
- PAN-OS 10.0 (EoL)
- PAN-OS 10.1
- PAN-OS 10.2
- PAN-OS 11.0
- PAN-OS 11.1
- PAN-OS 11.2
- PAN-OS 8.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 9.1
Create a Policy-Based Forwarding Rule
Create a policy-based forwarding rule to direct traffic
to a specific egress interface on the firewall and override the
default path for the traffic.
Use a PBF rule
to direct traffic to a specific egress interface on the firewall
and override the default path for the traffic.
Before you
create a PBF policy rule, make sure you understand that the set
of IPv4 addresses is treated as a subset of the set of IPv6 addresses,
as described in detail in Policy.
- Create a Policy-Based Forwarding (PBF) rule.When creating a PBF rule, you must specify a name for the rule, a source zone or interface, and an egress interface. All other components are either optional or have a default value.You can specify the source and destination addresses using an IP address, an address object, or an FQDN.
- SelectandPoliciesPolicy Based ForwardingAdda PBF policy rule.
- Give the rule a descriptive name (General).
- SelectSourceand configure the following:
- Select theType(ZoneorInterface) to which you will apply the forwarding policy and specify the relevant zone or interface. If you want to enforce symmetric return, you must select a source interface.Only Layer 3 interfaces support PBF; loopback interfaces do not support PBF.
- (Optional) Specify theSource Addressto which the PBF rule applies. For example, a specific IP address or subnet IP address from which you want to forward traffic to the interface or zone specified in this rule.ClickNegateto exclude one or moreSource Addressesfrom the PBF rule. For example, if your PBF rule directs all traffic from the specified zone to the internet,Negateallows you to exclude internal IP addresses from the PBF rule.The evaluation order is top down. A packet is matched against the first rule that meets the defined criteria; after a match is triggered, subsequent rules are not evaluated.
- (Optional)Addand select theSource Useror groups of users to whom the policy applies.
- SelectDestination/Application/Serviceand configure the following:
- Destination Address—By default, the rule applies toAnyIP address. ClickNegateto exclude one or more destination IP addresses from the PBF rule.
- AddanyApplicationandServicethat you want to control using PBF.We do not recommend application-specific rules for use with PBF because PBF rules may be applied before the firewall has enough information to determine the application. Whenever possible, use a service object, which is the Layer 4 port (TCP or UDP) used by the protocol or application. For more details, see Service Versus Applications in PBF.
- Specify how to forward packets that match the rule.If you are configuring PBF in a multi-VSYS environment, you must create separate PBF rules for each virtual system (and create the appropriate Security policy rules to enable the traffic).
- SelectForwarding.
- Set theActionto take when matching a packet:
- Forward—Directs the packet to the specifiedEgress Interface.
- Forward to VSYS(On a firewall enabled for multiple virtual systems)—Select the virtual system to which to forward the packet.
- Discard—Drops the packet.
- No PBF—Excludes packets that match the criteria for source, destination, application, or service defined in the rule. Matching packets use the route table instead of PBF; the firewall uses the route table to exclude the matched traffic from the redirected port.
- To trigger the specifiedActionat a daily, weekly, or non-recurring frequency, create and attach aSchedule.
- ForNext Hop, select one of the following:
- IP Address—Enter an IP address or select an address object of type IP Netmask to which the firewall forwards matching packets. An IPv4 address object must have a /32 netmask and an IPv6 address object must have a /128 netmask.
- FQDN—Enter an FQDN (or select or create an address object of type FQDN) to which the firewall forwards matching packets. The FQDN can resolve to an IPv4 address, an IPv6 address, or both. If the FQDN resolves to both IPv4 and IPv6 addresses, then the PBF rule has two next hops: one IPv4 address and one IPv6 address. You can use the same PBF rule for both IPv4 and IPv6 traffic. IPv4 traffic is forwarded to the IPv4 next hop; IPv6 traffic is forwarded to the IPv6 next hop.This FQDN must resolve to an IP address that belongs to the same subnet as the interface you configured for PBF; otherwise, the firewall rejects the resolution and the FQDN remains unresolved.The firewall uses only one IP address (from each IPv4 or IPv6 family type) from the DNS resolution of the FQDN. If the DNS resolution returns more than one address, the firewall uses the preferred IP address that matches the IP family type (IPv4 or IPv6) configured for the next hop. The preferred IP address is the first address the DNS server returns in its initial response. The firewall retains this address as preferred as long as the address appears in subsequent responses, regardless of order.
- None—No next hop mean the destination IP address of the packet is used as the next hop. Forwarding fails if the destination IP address is not in the same subnet as the egress interface.
- (Optional) Enable monitoring to verify connectivity to a target IP address or to theNext HopIP address if no IP address is specified. SelectMonitorand attach a monitoringProfile(default or custom) that specifies the action when the monitored address is unreachable.
- You canDisable this rule if nexthop/monitor ip is unreachable.
- Enter a targetIP Addressto monitor.
TheEgress Interfacecan have both IPv4 and IPv6 addresses and theNext HopFQDN can resolve to both IPv4 and IPv6 addresses. In this case:- If the egress interface has both IPv4 and IPv6 addresses and the next hop FQDN resolves to only one address family type, the firewall monitors the resolved IP address. If the FQDN resolves to both IPv4 and IPv6 addresses but the egress interface has only one address family type address, the firewall monitors the resolved next hop address that matches the address family of the egress interface.
- If both the egress interface and next hop FQDN have both IPv4 and IPv6 addresses, the firewall monitors the IPv4 next hop address.
- If the egress interface has one address family address and the next hop FQDN resolves to a different address family address, the firewall does not monitor anything.
- (Required for asymmetric routing environments; otherwise, optional)Enforce Symmetric ReturnandAddone or more IP addresses in theNext Hop Address List. You can add up to 8 next-hop IP addresses; tunnel and PPoE interfaces are not available as a next-hop IP address.Enabling symmetric return ensures that return traffic (such as from the Trust zone on the LAN to the internet) is forwarded out through the same interface through which traffic ingresses from the internet.
- Commityour changes. The PBF rule is in effect.