Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Matlu
Advisor

PBR Rules

Hello, everyone.

I currently have 2 links in our GW.

ISP + MPLS

We have a VLAN 192.168.8.0/24, which currently travels over the MPLS link.
From this VLAN, we have 1 IP 192.168.8.130 to which we have configured 1 PBR so that it's traffic can be output to the Internet, through the ISP link.

The problem is that having configured this PBR rule, the IP in question has lost connectivity with other VLANs that were already working prior to the configuration.

PBR1.png

Is there any way to achieve through the PBR, tell the GW to only apply the PBR for Internet traffic (such as HTTPS, HTTP, DNS), and that any other traffic continues to work with the normal routing table?

Thanks for any comments.

0 Kudos
2 Replies
the_rock
Legend
Legend

I think simple network diagram would help here.

Andy

0 Kudos
Wolfgang
Authority
Authority

You can use a lot of parameters in your PBR, see Policy-Based Routing and Application-Based Routing in Gaia (checkpoint.com)

  • Inbound Interface at which a packet arrives.
  • Source IPv4 address and subnet mask.
  • Destination IPv4 address and subnet mask.
  • Destination Service Port Number (e.g., FTP, SSH, Telnet).
  • Protocol Number (e.g., TCP, UDP, ICMP).
  • Firewall Rule Number (introduced as a hidden feature in R80.40 for Application-Based Routing, such as Office365).
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events