06-01-2022 04:29 AM
Hi team,
we have a plan to migrate some of the subnets from FPR to the next hop(from Radware to F5). I have doubt that if I create PBR that will work nicely for outbound traffic but I am not sure for inbound traffic. Please let me know any solution or any info on this.
06-01-2022 04:44 AM
Hi
Which devices we are talking about and version? A simple topology also helps.
06-01-2022 04:48 AM - edited 06-01-2022 04:49 AM
PBR should work as expected for inbound, make sure outbound also taken care.
Most cases we do static NAT right, can you should some example of your setup ? and goal ?
This required some testings, make sure the flows works as expected.
06-01-2022 10:04 PM
Hi,
We are using FMC 2600 in HA with version 6.6.5, and FTD 4125 in HA. version 6.6.4. We configured the Flexconfig for outbound traffic towards F5.
we have a default route towards Radware 10.10.10.4.
The outbound traffic is working fine for some of the LAN subnets towards F5 10.10.10.9 using Flexconfig.
we do not use NAT at Firewall. we will configure NAT at F5 itself. we have some servers which require inbound traffic also. If i configure flexconfig for outbound traffic to DMZ servers, does inbound work or not that I am not sure.
06-02-2022 12:14 AM
Hello
With PBR you will usually incur asymmetric traffic paths if the PBR'd traffic next hop device has a different default egress path other then the ingress path it is receiving from the policy routed traffic.
06-02-2022 03:42 AM
In your case PBR must be applied in LAN interface for LAN Server A to force route traffic to Nexthop A for outbound internet access, In this scenario if a fresh inbound connection received at FPR through WAN interface the traffic will be forwarded LAN server A and when the return traffic hits the FPR in LAN interface it will not match in the PBR but take the default route and forwarded to Nexthop B.
I have experienced the same issue in past and understood from team that PBR meant for initiated traffic.
06-09-2022 05:57 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide