<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DIP NAT on inter vsys traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dip-nat-on-inter-vsys-traffic/m-p/484708#M104447</link>
    <description>&lt;P&gt;Thanks for the answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry I didn't mention my current version, it's 8.1 and FW is PA-5250..&lt;/P&gt;&lt;P&gt;And I found some weird log, which is "session end reason is unknown."&lt;/P&gt;&lt;P&gt;Guess that hit the bug, and it looks like not every traffic but some traffics definitely are affected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 May 2022 01:30:56 GMT</pubDate>
    <dc:creator>yhlee1</dc:creator>
    <dc:date>2022-05-04T01:30:56Z</dc:date>
    <item>
      <title>DIP NAT on inter vsys traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dip-nat-on-inter-vsys-traffic/m-p/484458#M104430</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a FW that has many nat rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I found a bug,&amp;nbsp;pan-130550:&lt;/P&gt;&lt;DIV class=""&gt;(&lt;SPAN&gt;PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls&lt;/SPAN&gt;) For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;Workaround:&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Mine is PA-5250 and I already have DIP NAT rules for inter vsys traffic, and it looks like working well(hit counts, log..)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Anyone knows about that bug? Does it impact on every traffic or sometimes FW cannot perform NAT?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;The workaround of the bug not works for me, I can't convert every DIP NAT rule to DIPP in my FW...&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 03 May 2022 08:58:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dip-nat-on-inter-vsys-traffic/m-p/484458#M104430</guid>
      <dc:creator>yhlee1</dc:creator>
      <dc:date>2022-05-03T08:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: DIP NAT on inter vsys traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dip-nat-on-inter-vsys-traffic/m-p/484650#M104442</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/103730"&gt;@yhlee1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This bug ID has been carried through PAN-OS since the hardware platforms were released with the newer FPGAs. If you aren't running into an issue on your current release, I wouldn't be overly worried about it moving forward.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 20:27:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dip-nat-on-inter-vsys-traffic/m-p/484650#M104442</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-05-03T20:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: DIP NAT on inter vsys traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dip-nat-on-inter-vsys-traffic/m-p/484708#M104447</link>
      <description>&lt;P&gt;Thanks for the answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry I didn't mention my current version, it's 8.1 and FW is PA-5250..&lt;/P&gt;&lt;P&gt;And I found some weird log, which is "session end reason is unknown."&lt;/P&gt;&lt;P&gt;Guess that hit the bug, and it looks like not every traffic but some traffics definitely are affected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 01:30:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dip-nat-on-inter-vsys-traffic/m-p/484708#M104447</guid>
      <dc:creator>yhlee1</dc:creator>
      <dc:date>2022-05-04T01:30:56Z</dc:date>
    </item>
  </channel>
</rss>

