How to Configure PBF in Multi Vsys Configuration
This document describes how to configure PBF in a multi vsys setup on the Palo Alto Networks device.
Example network scenario (Palo Alto Networks device represented by "PA"):
Client ---- PA (vsys_lan) ---- PA (vsys_internet) ---- Internet
- Create 2 virtual systems and make sure they are visible to each other
- Each vsys has it's own VR
- Create at least 1 Layer3 zone and 1 external zone for each vsys
- Step4: We need to create 2 PBF rules. (1 for each vsys)
The first PBF rule will route the traffic from the LAN vsys to the Internet vsys, the second PBF rule will forward the traffic to it's default gateway. If you don't configure the second PBF rule, your traffic will get dropped on the Palo Alto Networks device.
- Make sure you create security policies on both vsys's that allow the traffic.