<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic cannot return in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/506080#M105629</link>
    <description>&lt;P&gt;Hi, it was solved with NAT SOURCE rule. Masking like a Lan subnet. Thks..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apazmino_1-1656092627600.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41974i5D354768ED944B66/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="apazmino_1-1656092627600.png" alt="apazmino_1-1656092627600.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jun 2022 17:43:53 GMT</pubDate>
    <dc:creator>apazmino</dc:creator>
    <dc:date>2022-06-24T17:43:53Z</dc:date>
    <item>
      <title>Traffic cannot return</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/505932#M105619</link>
      <description>&lt;P&gt;Hi Folks I have the next topology. The problem is the return traffic when I connect via GlobalProtect and I get a client IP 10.81.235.x. This IP cannot connect with a web server that is in the LAN, but this LAN is external through a data link routing.&lt;/P&gt;&lt;P&gt;In the other side, owner of web server 192.168.36.38 they don't want to include subnet GP 10.81.235.x in their route tables for propagation due to internal security policies. Currently, communication is succesfull between LAN internal to LAN external, but GP to LAN external (192.168.36.x) is not completing.&lt;/P&gt;&lt;P&gt;In logs we have security rule that show me allow with application incomplete and session end reason Aged out.&lt;/P&gt;&lt;P&gt;Is possible to use a NAT rule to force communication and avoid session loss or PBF with symetric return? What option could you suggest me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 02:40:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/505932#M105619</guid>
      <dc:creator>apazmino</dc:creator>
      <dc:date>2022-06-24T02:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic cannot return</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/506013#M105624</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191214"&gt;@apazmino&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Probably stupid question, but can you clarify for me what do you mean by "LAN is external through a data link routing"?&lt;/P&gt;
&lt;P&gt;It is hard to understand your topology with provided information, without any diagram, at least for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what I understand your problem definately sounds like the destionation doesn't know how to route back the traffic, which could be solved with NAT. It is very hard to imagine how PBF could help in this situation so go for the NAT and agree with the remote site on prefix that can be used for translating your GP IP pool.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 10:39:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/506013#M105624</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-06-24T10:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic cannot return</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/506027#M105626</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="topology return.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41967i7804E1BB6B548B73/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="topology return.png" alt="topology return.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HI Astardzhiev, thanks for your response. When I refer to external lan, I tried to explain with this topology, lan external come to be one external subnet that does not belong to my side, otherwise, lan external is other subnet connected via data link but is within LAN_zone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then, to clarify I attach diagram, the question is: In the return from subnet 192.168.36.x could I use Source or destination NAT?.. According to your suggestion is not possible with PBF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks so much&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 12:12:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/506027#M105626</guid>
      <dc:creator>apazmino</dc:creator>
      <dc:date>2022-06-24T12:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic cannot return</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/506080#M105629</link>
      <description>&lt;P&gt;Hi, it was solved with NAT SOURCE rule. Masking like a Lan subnet. Thks..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apazmino_1-1656092627600.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41974i5D354768ED944B66/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="apazmino_1-1656092627600.png" alt="apazmino_1-1656092627600.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 17:43:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/506080#M105629</guid>
      <dc:creator>apazmino</dc:creator>
      <dc:date>2022-06-24T17:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic cannot return</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/506209#M105647</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191214"&gt;@apazmino&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Glad you solved your problem. Add some clarification:&lt;/P&gt;
&lt;P&gt;- You &lt;U&gt;have to&lt;/U&gt; use source NAT, because you need to change the source address for which the server will try to send reply back.&lt;/P&gt;
&lt;P&gt;- The purpose of PBF is if you want to route given traffic, based on some kind of policy - for example any traffic from given source network. But PBF cannot help you if destination network doesn't have route back or don't want to install proper routing for your source network.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 20:35:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-cannot-return/m-p/506209#M105647</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-06-25T20:35:37Z</dc:date>
    </item>
  </channel>
</rss>

