- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I'm having trouble getting the PBR configuration to work and could use some help.
Network Configuration
The firewall is connected as follows:
eth1: Internet
eth2: Local Network (access to 10.100.0.0/16 via 10.100.1.1/24)
Mgmt: Management Network (10.100.254.0/24)
What I Want to Achieve
I want to synchronize time with the NTP server located at 10.100.253.1 through the Management network. However, due to the current routing, access to the NTP server goes through eth2. I want to correct this using PBR.
Current Configuration
Static Route
default via [eth1 nexthop]
10.100.0.0/16 via 10.100.1.1
PBR Table
set pbr table MgmtPbrTable static-route 10.100.253.1/32 nexthop gateway address 10.100.254.254 priority 1
# I have tried the following three patterns, but none of them worked:
Default route via 10.100.254.254
To 10.100.253.0/24 via 10.100.254.254
To 10.100.253.1/32 via 10.100.254.254
PBR Rule
set pbr rule priority 1 match from 10.100.254.1/32
set pbr rule priority 1 match to 10.100.253.1/32
set pbr rule priority 1 action table MgmtPbrTable
Additional Information
When I added the static route 10.100.253.1/32 via 10.100.254.254, access worked correctly. However, this is not a viable solution because I want access from the Internet to the NTP server to go through eth2 as usual.
Note Locally-generated traffic is considered a limitation of PBR per sk167135
Perhaps a normal static route for the /32 can work for you (may also require an anti-spoofing exception).
If you're using NAT, check if the PBR policy is considering the IP before or after a NAT.
Test, if possible, changing the PBR to consider (or not) the NAT .
Best regards,
Note Locally-generated traffic is considered a limitation of PBR per sk167135
Perhaps a normal static route for the /32 can work for you (may also require an anti-spoofing exception).
Thank you for your prompt response and for clarifying the PBR limitation for locally-generated traffic as outlined in sk167135.
I’ll look into using a normal static route for the /32, and consider the anti-spoofing exception if needed.
I appreciate your help!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY