<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue Nat Outbond Palo Alto in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591263#M3389</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1476559475"&gt;@f.niam&lt;/a&gt;&amp;nbsp;Why you have both directions NAT configured? Do you want it to be available from Internet also?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;During issue time, did you check the traffic logs to understand what's happening? Is it matching NAT statement when issue is present ?&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2024 15:17:34 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2024-07-05T15:17:34Z</dc:date>
    <item>
      <title>Issue Nat Outbond Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591213#M3388</link>
      <description>&lt;P&gt;i got an issue, while sometimes my fortimail is unable connect to internet, and for my fortimail to able connect to internet again i disable and enable my nat policy, is there any bug related to that because i got this every day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="niam77_0-1720093967736.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60669i71B08236A3F5A0E9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="niam77_0-1720093967736.png" alt="niam77_0-1720093967736.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;here is my nat policy&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 11:54:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591213#M3388</guid>
      <dc:creator>f.niam</dc:creator>
      <dc:date>2024-07-04T11:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Nat Outbond Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591263#M3389</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1476559475"&gt;@f.niam&lt;/a&gt;&amp;nbsp;Why you have both directions NAT configured? Do you want it to be available from Internet also?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;During issue time, did you check the traffic logs to understand what's happening? Is it matching NAT statement when issue is present ?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 15:17:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591263#M3389</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2024-07-05T15:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Nat Outbond Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591280#M3390</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Disable the policy NAT 85 in your picture as it is not required. Also I hope this external IP is used only for the Fortimail, if yes, set the Bi-Directional to yes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 18:57:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591280#M3390</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-07-05T18:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Nat Outbond Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591288#M3391</link>
      <description>&lt;P&gt;yes, i need fortimail to get internet, because during issue my fortimail can't send email to outbond and while i trace from fortimail packet stop at palo alto, and while i disable and re-enable nat policy no.86 my fortimail is back to normal and can send email to outbond, while in my palo alto traffci log it show application incomplete&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 20:25:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591288#M3391</guid>
      <dc:creator>f.niam</dc:creator>
      <dc:date>2024-07-05T20:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Nat Outbond Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591289#M3392</link>
      <description>&lt;P&gt;unfortunately, my external ip public is used by two ip address, and here is my detail issue,&lt;SPAN&gt;&amp;nbsp;my fortimail can't send email to outbond and while i trace from fortimail packet stop at palo alto, and while i disable and re-enable nat policy no.86 my fortimail is back to normal and can send email to outbond&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 20:27:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591289#M3392</guid>
      <dc:creator>f.niam</dc:creator>
      <dc:date>2024-07-05T20:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Nat Outbond Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591298#M3393</link>
      <description>&lt;P&gt;Your policy names are confusingly reversed (regarding what is in/out) but that's not relevant here. I don't see anything specifically wrong here and as you're saying - it is an intermittent/runtime issue, it works and then it does not work - meaning as if the configuration is fine, just that something happens in the data plane.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This tells me that some in-depth debugging of the sessions and packets is required, you can take packet captures, trace down and investigate sessions, etc., but it may also be basis for a support case. If you get lucky, they may find something in the tech support file or it may be a known issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand you can't initiate this situation to reproduce it, but once it happens, you can keep if for some time so that it can be investigated. E-mail servers usually try to re-send an e-mail for 4 to 8 hours so if you keep it broken for a few hours, there should only be a delay but no actual data loss for the users.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2024 13:41:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/issue-nat-outbond-palo-alto/m-p/591298#M3393</guid>
      <dc:creator>jkvalk59s</dc:creator>
      <dc:date>2024-07-06T13:41:52Z</dc:date>
    </item>
  </channel>
</rss>

