<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBR Limitations question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-Limitations-question/m-p/79101#M6093</link>
    <description>The problem is that VPN Routing and regular routing somewhat conflict with one another as they operate at a similar area in the packet flow and the behavior may not be as expected.&lt;BR /&gt;Possible it still works, but it's an unsupported configuration.&lt;BR /&gt;&lt;BR /&gt;Locally generated traffic refers to traffic that comes from the gateway itself.</description>
    <pubDate>Sat, 21 Mar 2020 07:24:54 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-03-21T07:24:54Z</dc:date>
    <item>
      <title>PBR Limitations question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-Limitations-question/m-p/78920#M6079</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;I have a question regarding the use of PBR and their limitations&lt;/P&gt;&lt;P&gt;According to sk100500, the documented limitations regarding the use of PBR, include Domain Based VPN.&lt;/P&gt;&lt;P&gt;I currently have a client that has two ISPs and two LAN network segments (LAN1 and LAN2); the customer wants to segment their traffic, so LAN1 uses only ISP1 and LAN2 uses only ISP2. However, LAN1 using ISP1 has multiple s2s VPNs (Domain based) configured.&lt;/P&gt;&lt;P&gt;The question is, if I only use PBR to route LAN2 traffic through ISP2, will the VPNs established on LAN1 through ISP1 be affected?, or will PBR only affects the traffic in which it is applied? (in this case, we are attempting to apply PBR only through LAN2--&amp;gt;ISP2)&lt;/P&gt;&lt;P&gt;Extending the context of the question, PBR limitations only applies in traffic in which PBR rules are applied? or affects the entire traffic passing through the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 04:51:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-Limitations-question/m-p/78920#M6079</guid>
      <dc:creator>Roberto_Cardozo</dc:creator>
      <dc:date>2020-03-20T04:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: PBR Limitations question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-Limitations-question/m-p/78925#M6080</link>
      <description>Hi again&lt;BR /&gt;&lt;BR /&gt;By the way, another question is: what exactly is the limitation "locally-generated" traffic referring to?&lt;BR /&gt;&lt;BR /&gt;Thank you again</description>
      <pubDate>Fri, 20 Mar 2020 05:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-Limitations-question/m-p/78925#M6080</guid>
      <dc:creator>Roberto_Cardozo</dc:creator>
      <dc:date>2020-03-20T05:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: PBR Limitations question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-Limitations-question/m-p/79101#M6093</link>
      <description>The problem is that VPN Routing and regular routing somewhat conflict with one another as they operate at a similar area in the packet flow and the behavior may not be as expected.&lt;BR /&gt;Possible it still works, but it's an unsupported configuration.&lt;BR /&gt;&lt;BR /&gt;Locally generated traffic refers to traffic that comes from the gateway itself.</description>
      <pubDate>Sat, 21 Mar 2020 07:24:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-Limitations-question/m-p/79101#M6093</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-21T07:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: PBR Limitations question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-Limitations-question/m-p/79103#M6094</link>
      <description>When you make sure that for the VPN remote peers the routing is properly set to ISP1, this should work just fine. &lt;BR /&gt;The point is that routing for the encrypted traffic will follow the route for the remote peer and cannot be rerouted by PBR.</description>
      <pubDate>Sat, 21 Mar 2020 08:11:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-Limitations-question/m-p/79103#M6094</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-21T08:11:48Z</dc:date>
    </item>
  </channel>
</rss>

