<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: strange behavior of bidirectional NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/482321#M104272</link>
    <description>&lt;P&gt;show some screenshots of your NAT, Security rule&amp;nbsp; and log, that would help in proffering solution (gray out sensitive details)&lt;/P&gt;</description>
    <pubDate>Mon, 25 Apr 2022 14:29:15 GMT</pubDate>
    <dc:creator>S_Alad</dc:creator>
    <dc:date>2022-04-25T14:29:15Z</dc:date>
    <item>
      <title>strange behavior of bidirectional NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/481738#M104196</link>
      <description>&lt;P&gt;hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today I've spotted weird behavior:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have 2 static bidirectional NAT translations between UNTRUST and DMZ interfaces for public IPs. Also we are allowing certain applications in for those public NATed IPs from any IP addresses using only applications and not service/ports. From logs we see that traffic which is properly allowed and working has UNTRUST as source zone and DMZ as destination zone. This works fine. But for some of connections we see that source and destination zones are UNTRUST and traffic is been dropped as we have specific rule to drop such traffic within same zone. Both destination IPs/ports are the same every time. I would assume actual forward decision is done incorrectly, hence part of the traffic been denied. Also denied traffic in logs is matched as 'not-applicable' in application column - which is understandable, but working not how it should.&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assume PaloAlto should perform kind of forwarding decision to find out what zone destination interface belongs to. It might be regular ARP lookup or routing lookup. Since DMZ interface/subnet are directly connected to a firewall, there's no routing to DMZ hosts, this means it either regular NAT is broken or ARP cache, but as part of the traffic is going through normally I doubt that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts or hints here please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 19:26:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/481738#M104196</guid>
      <dc:creator>Andreikin</dc:creator>
      <dc:date>2022-04-21T19:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: strange behavior of bidirectional NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/481796#M104203</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206623"&gt;@Andreikin&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the information provided, it sounds like the traffic is not matching the NAT rule.&amp;nbsp; Could you add the "NAT Applied" column under Monitor &amp;gt; Logs &amp;gt; Traffic and let me know what is says for the allowed and denied sessions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 00:30:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/481796#M104203</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-04-22T00:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: strange behavior of bidirectional NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/481835#M104211</link>
      <description>&lt;P&gt;Hello TomYoung,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply. The NAT applied shows NO for sessions within same zone and YES for sessions between DMZ and Untrust. That's the whole point actually - SOME connections for the same public IP (NATed bidirectionally to private) have their NAT applied and marked as allowed, some of them - don't and marked dropped. Within same NAT translation, which is bidirectional and does not involve any source changes or ports. Just regular 1:1 mapping between Public and Private IPs. So it is hard for me to understand why there's a difference in zone selection while NAT translation is the same.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 06:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/481835#M104211</guid>
      <dc:creator>Andreikin</dc:creator>
      <dc:date>2022-04-22T06:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: strange behavior of bidirectional NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/482024#M104231</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206623"&gt;@Andreikin&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the information.&amp;nbsp; You have confirmed that the traffic with "NO" NAT Applied is not matching the NAT rule (or any NAT rule).&amp;nbsp; The difference is not zone selection, but NAT rule selection.&amp;nbsp; The destination zone forwarding decision is based upon the NAT rule, if it matches.&amp;nbsp; I hear you that the NAT rule is very basic with just real and mapped IP address only.&amp;nbsp; There is nothing else which would cause the traffic not to match it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&amp;nbsp; If the answer is not apparent in the GUI, use the CLI command "show session id" followed by the session number of a working and non-working session and compare every line.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 16:24:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/482024#M104231</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-04-22T16:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: strange behavior of bidirectional NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/482273#M104265</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's no ports or anything like this affecting NAT translation. We just simply NAT private IP to public IP for a same host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As mentioned we still not clear why some of the traffic been matched NAT translation (and shows proper zones in logs) and some of them don't. Will have a session with support to day to go through the case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 08:34:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/482273#M104265</guid>
      <dc:creator>Andreikin</dc:creator>
      <dc:date>2022-04-25T08:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: strange behavior of bidirectional NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/482321#M104272</link>
      <description>&lt;P&gt;show some screenshots of your NAT, Security rule&amp;nbsp; and log, that would help in proffering solution (gray out sensitive details)&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 14:29:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/482321#M104272</guid>
      <dc:creator>S_Alad</dc:creator>
      <dc:date>2022-04-25T14:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: strange behavior of bidirectional NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/482328#M104274</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Also check the logs to see which nat policy is being applied to the traffic. It could be the NAT policy to too low on the list. Just like security policies, the NAT checks top down, left to right. Once it matches, it uses it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 14:42:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior-of-bidirectional-nat/m-p/482328#M104274</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-04-25T14:42:31Z</dc:date>
    </item>
  </channel>
</rss>

