Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gorazd
Explorer

ABR (Application Based Routing): "PBR_" rules don't show up on firewalls

Dear fellow engineers,

I try to implement hidden feature - ABR (Application Based Routing) - as per sk167135, but the "PBR_" rules that I configure on the management station, don't show up on firewalls in Gaia GUI, when I try to connect a PBR route with a Firewall Rule. "rtgpbrd" prosess is running, but file "/tmp/fwpbrrules.conf" doesn't exist, nor an entry in the database ("dbget -arv fwrules" doesn't show anything)

I followed SK step-by-step, unlocking the feature with dbset commands, rebooting the firewalls, configure PBR_ rules in the management and pushing the policy.

I have R81.10 both management and firewalls that run in ClusterXL cluster and the management is MDS. I tried to implement rules that start "PBR_" on the domain level and also in the global MDS policy.

One non-usual feature that I use and that caused me many sleepless nights is mdps, but I can't see any connection between mdps and ABR. Just to be sure, I entered dbset commands in both management and data environment.

Any ideas, what I can try next?

 

0 Kudos
7 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Unfortunately the table in section 5 of sk167135 suggests this combination (MDPS+ABR) isn't supported.

 

CCSM R77/R80/ELITE
0 Kudos
Gorazd
Explorer

I reconfigured the firewalls and removed MDPS. But there is still the same behavior, "/tmp/fwpbrrules.conf" doesn't exist.

I was thinking of another line from the table "Supported Functionality and Limitations" you mentioned. On the line 18, it is stated that "Rule Base hierarchy (inner layer structure)" is not supported. The question is, are MDS Global Rules and Domain rules considers as "inner layer structure"? To be sure, I configured a rule that start with "PBR_" in both, Global Access Rule policy and Domain Access Rule policy... still no file on the firewalls and no "PBR_" rule in drop-down list... :S

Any ideas?

0 Kudos
PhoneBoy
Admin
Admin

I suspect this feature does not support the use of MDS Global Rules or Domain Rules.

0 Kudos
mohammed1987
Contributor

Hi community, i used to face the same issu (i think)

i were using several blade (license sandblast) 

having acces control security rules and url/application rules in the same customized policy security Layer.

well the PBR_ rules are matched and the trafic never uses the PBR related policies and it takes the main routing table. 

 

what i have done (helped by claude) : 

Ordered Layers

This is the design specifically intended for this exact use case, and it represents the architectural conclusion of the entire ABR implementation.

Layer 1 – Network (Existing, Simplified)

The first layer should contain only pure Layer 3/Layer 4 network rules, including:

  • Standard network security rules
  • The PBR_ rules
  • The Cleanup rule

The objective is that the very first packet always receives a definitive match within this layer.

This guarantees that the ABR/PBR routing mark is applied immediately and consistently, before any application or URL inspection occurs. As a result, policy-based routing operates reliably for all traffic.

Layer 2 – Application / URL Filtering

The second ordered layer should contain:

  • The Application Control & URL Filtering rules
  • The category-based Drop rule (e.g., Adult/Sex, Gambling, etc.)
  • A final Accept Any rule

This final Accept rule is mandatory because, with Ordered Layers, a connection must be accepted by every layer in order to proceed. Without a final Accept rule, any traffic that does not explicitly match another rule in this layer would be implicitly dropped.

The resulting packet flow is therefore:

  1. The connection matches a Network rule in Layer 1.
  2. The ABR/PBR mark is immediately assigned.
  3. Routing decisions are made using the correct policy-based route.
  4. A few packets later, once the TLS SNI, HTTP Host header, or URL category has been identified, Layer 2 evaluates the application and URL policy.
  5. If the traffic matches a blocked category, it is dropped.
  6. Otherwise, it reaches the final Accept rule and is allowed.

This architecture provides both correct policy-based routing and application/URL filtering for all users.

SmartConsole Implementation

In Access Control Policy:

  1. Open Manage Layers.
  2. Create a new Ordered Layer.
  3. Enable the Application Control & URL Filtering blades for this layer.
  4. Move all category-based blocking rules (Adult, Gambling, etc.) into this new layer.
  5. Add a final Accept Any rule at the bottom of the layer.
  6. Install the Access Policy.

This design ensures that ABR/PBR decisions are always taken on the first packet, while Application Control and URL Filtering continue to inspect and enforce policies once sufficient application information becomes available. It is the recommended architecture for environments combining Policy-Based Routing with Application Control and URL Filtering.

 

and it works for me. 

 

0 Kudos
doumhh-17
Explorer

Hi, did you get it working, I´m having a similiar issue: 

PBR is working, ABR not

all the checks from sk167135 are  looking good, except File /tmp/fwpbrules.conf is not being created.

PBR Action Table 1 Gateway is next Hop IP

PBR Action Table 2 Gateway is vpnt1

I want to create Policy Rule to merge "Firewall Rule PBR_Bypass" to use Table 1.

[Expert@hostname:0]# cat /tmp/fwpbrrules.conf

cat: /tmp/fwpbrrules.conf: No such file or directory

[Expert@hostname:0]# dbget -arv fwrules

fwrules:instance

fwrules:instance:default

fwrules:instance:default:rulenum

fwrules:instance:default:rulenum:9 t

fwrules:instance:default:rulenum:9:name PBR_Bypass

fwrules:instance:default:rulenum:9:uuid 20f7db3f-b822-49ce-8fb8-754fd227aa3b

[Expert@hostname:0]#

I don´t think that there are known Limitations relevant for my environment.

 

Im Smartviewtracker I see Drop Reasons like this: 

- Failed to enforce VPN policy (11)

- Connection terminated before detection: Insufficient data passed.
To learn more see sk113479.

 

 

0 Kudos
Golo_Koenigshof
Explorer

Same with me, the "PBR_" Rules are not showing up in the Gaia Portal, the ABR "Firewall Rules" dropdown is empty.

cat /tmp/fwpbrrules.conf -> No such file or directory
dbget -arv fwrules -> No reult (empty)

Did any of you find a solution?

0 Kudos
TRajkumar
Contributor
Contributor

Hi Everyone

 Me too having the same problem in R81.10.I followed the SK167135,

 cat /tmp/fwpbrrules.conf --- > shows No such file or directory

cat /tmp/pbr/fwpbrrules.conf.0 -- > gives the result. It show the firewall policy which i created.

dbget -arv fwrules --> Gives output

 

But on gaia PBR option "firewall rule" not available.

any one got solution for this issue?

Waiting for the reply:)

Thanks

Rajkumar

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events