<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Leak Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/573810#M115361</link>
    <description>&lt;P&gt;How many concurrent sessions you have?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show session all filter count yes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How is status of &lt;SPAN&gt;NAT IP pool cache?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show running ippool&lt;/P&gt;
&lt;P&gt;show running global-ippool&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CliQCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CliQCAS&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 21 Jan 2024 13:57:22 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2024-01-21T13:57:22Z</dc:date>
    <item>
      <title>NAT Leak Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/573788#M115353</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Been troubleshooting an issue with viewing live streams from cameras from one specific location.&amp;nbsp; We've had the system in place for awhile and it was working fine until recently.&amp;nbsp; Any time we try to establish a connection over tcp 960, it was failing.&amp;nbsp; I noticed in packet capture that the firewall was not performing NAT for that traffic.&amp;nbsp; I ran command "debug dataplane nat sync-ippool rule &amp;lt;rule name&amp;gt;" and now its working fine (at least temporarily).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While troubleshooting, we re-routed this traffic to another location that was working fine.&amp;nbsp; However, now when I view the NAT table on that firewall, I see "NAT pool is leaking!!!".&amp;nbsp; &amp;nbsp;It appears this location is now going to have an issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Running pan-os 10.1.11.&amp;nbsp; Seems we are running into a bug, but didn't see this listed in known issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advice would be appreciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2024 16:37:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/573788#M115353</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2024-01-20T16:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Leak Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/573810#M115361</link>
      <description>&lt;P&gt;How many concurrent sessions you have?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show session all filter count yes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How is status of &lt;SPAN&gt;NAT IP pool cache?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show running ippool&lt;/P&gt;
&lt;P&gt;show running global-ippool&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CliQCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CliQCAS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 13:57:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/573810#M115361</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-01-21T13:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Leak Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/573836#M115363</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So a few things, for the firewall with the initial issue, I don't recall the exact sessions/nat pool stats but they were both low.&amp;nbsp; After we routed traffic for that destination to one of our other sites,&amp;nbsp; I cleared all sessions to that destination.&amp;nbsp; However, my TCP sessions were still not being established.&amp;nbsp; Only way to resolve was to clear/reclaim the stale NAT buffers.&amp;nbsp; One thing we previously tried was to create a pool of public IPs.&amp;nbsp; This helped but only for a week.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the firewall where the traffic was rerouted to, where it was showing NAT Pool is Leaking,&amp;nbsp; it was using around 2200 out of&amp;nbsp;126798&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on the timing when this issue started, it appears to be related to the upgrade from 9.1 to 10.1&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 17:48:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/573836#M115363</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2024-01-21T17:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Leak Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/577025#M115813</link>
      <description>&lt;P&gt;Any update?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 13:39:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/577025#M115813</guid>
      <dc:creator>CareyWest</dc:creator>
      <dc:date>2024-02-12T13:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Leak Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/581352#M116360</link>
      <description>&lt;P&gt;not yet.&amp;nbsp; Seems like maybe it is fixed in 10.1.13, but I can't say for sure yet.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 14:21:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-leak-issue/m-p/581352#M116360</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2024-03-22T14:21:27Z</dc:date>
    </item>
  </channel>
</rss>

