<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Having problems with TCP port allowance in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580648#M116275</link>
    <description>&lt;P&gt;Hey Joerg,&lt;BR /&gt;Hope everything is okay with you and your family.&lt;BR /&gt;&lt;BR /&gt;I'm not sure if I understood your question, but I think I did.&lt;BR /&gt;I've internally tested the port for the local IPv4 (127.0.0.1) and it works just fine.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de ecrã 2024-03-16, às 16.30.05.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58432i7FB350F397CAF250/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Captura de ecrã 2024-03-16, às 16.30.05.png" alt="Captura de ecrã 2024-03-16, às 16.30.05.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Sat, 16 Mar 2024 16:31:18 GMT</pubDate>
    <dc:creator>ruiptoliveira</dc:creator>
    <dc:date>2024-03-16T16:31:18Z</dc:date>
    <item>
      <title>Having problems with TCP port allowance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580135#M116216</link>
      <description>&lt;P&gt;Good morning/afternoon/night to everyone.&lt;BR /&gt;&lt;BR /&gt;I'm using for the first time Palo Alto Firewall and I'm having some troubles allowing TCP port 2245.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the moment I have this NAT Rules:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de ecrã 2024-03-12, às 23.13.36.png" style="width: 735px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58260iC069DB345F7A1DE2/image-dimensions/735x105/is-moderation-mode/true?v=v2" width="735" height="105" role="button" title="Captura de ecrã 2024-03-12, às 23.13.36.png" alt="Captura de ecrã 2024-03-12, às 23.13.36.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and I have this Security Rules:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de ecrã 2024-03-12, às 23.14.26.png" style="width: 740px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58261iB89B035DF65D91EE/image-dimensions/740x37/is-moderation-mode/true?v=v2" width="740" height="37" role="button" title="Captura de ecrã 2024-03-12, às 23.14.26.png" alt="Captura de ecrã 2024-03-12, às 23.14.26.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: note that I also have some rules for TCP/UDP ports related to WHM and cPanel.&lt;BR /&gt;&lt;BR /&gt;Can someone tell me if I'm doing something wrong?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Other important infos&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;gp-public and gp-public-2 are the two public IP addresses that are associated to the server&lt;/LI&gt;
&lt;LI&gt;mainCyber_Private is the private IP for the server&lt;/LI&gt;
&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de ecrã 2024-03-12, às 23.15.36.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58262i6E671E6E3E1C7030/image-dimensions/800x28/is-moderation-mode/true?v=v2" width="800" height="28" role="button" title="Captura de ecrã 2024-03-12, às 23.15.36.png" alt="Captura de ecrã 2024-03-12, às 23.15.36.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;STRONG&gt;Monitor:&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de ecrã 2024-03-12, às 23.17.58.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58263i4246654DE11C8AF2/image-dimensions/800x20/is-moderation-mode/true?v=v2" width="800" height="20" role="button" title="Captura de ecrã 2024-03-12, às 23.17.58.png" alt="Captura de ecrã 2024-03-12, às 23.17.58.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;I don't have a "private firewall" on the server&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;The server is listening on that port and that port can be accessed internally:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de ecrã 2024-03-12, às 23.21.38.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58264i62A6790C22610372/image-dimensions/800x42/is-moderation-mode/true?v=v2" width="800" height="42" role="button" title="Captura de ecrã 2024-03-12, às 23.21.38.png" alt="Captura de ecrã 2024-03-12, às 23.21.38.png" /&gt;&lt;/span&gt; 
&lt;P&gt; &lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de ecrã 2024-03-12, às 23.22.02.png" style="width: 660px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58265iBD45A82F3FEB162C/image-dimensions/660x554/is-moderation-mode/true?v=v2" width="660" height="554" role="button" title="Captura de ecrã 2024-03-12, às 23.22.02.png" alt="Captura de ecrã 2024-03-12, às 23.22.02.png" /&gt;&lt;/span&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 12 Mar 2024 23:22:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580135#M116216</guid>
      <dc:creator>ruiptoliveira</dc:creator>
      <dc:date>2024-03-12T23:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Having problems with TCP port allowance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580150#M116220</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1372958119"&gt;@ruiptoliveira&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From a quick glance, your NAT and Security Policy looks good. I'm assuming one of those IPs in the destination is the true source IP (internal) of the server and I see the traffic is being allowed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you click on detailed log view of the traffic, can you verify NAT is forwarding to the correct private IP. Also check if the traffic shows it show bytes sent, but not returned? If none are being returned then there could be an issue with the traffic getting down to the private server or an issue with the private server itself. Do you have any L3 devices between the firewall and the server? I see the localhost test shows the server is listening on the service port. Can you test from another host that doesn't traverse the Palo to get to the server? If that test works, could you run a tcpdump on the private server to see if you see the forwarded packets getting there? If so, I would verify that the server has a default gateway configured so it knows to point the return traffic up through your Palo since I see the public true source IP will be going through the Palo. You can test out L3 issues by applying a SNAT translation to the inside interface of your Palo and see if your traffic is successful then.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 05:39:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580150#M116220</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-03-13T05:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Having problems with TCP port allowance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580166#M116223</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The NAT rule let me assume, that you are using IPv4. On the other hand the "curl" command was using IPv6. Is the given port reachable w/ IPv4 as well?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 07:46:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580166#M116223</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2024-03-13T07:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Having problems with TCP port allowance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580646#M116274</link>
      <description>&lt;P&gt;Hello Jay,&lt;BR /&gt;Hope everything's good with you and your family/friends.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've followed your advice to check the detailed logs of monitor (to be honest, for some reason, I never went there), and I found something that I think is odd (the source port is 51238 and I'm not sure if it is supposed to be like this since I'm searching on the web for DOMAIN.COM:2245 or using Postman for the domain:2245 or ip:2245).&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-03-13 at 17.16.33.jpeg" style="width: 568px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58429iB4EF6F18D192FB06/image-dimensions/568x287/is-moderation-mode/true?v=v2" width="568" height="287" role="button" title="WhatsApp Image 2024-03-13 at 17.16.33.jpeg" alt="WhatsApp Image 2024-03-13 at 17.16.33.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-03-13 at 17.19.05.jpeg" style="width: 561px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58431iC4EA30545C6AC048/image-dimensions/561x230/is-moderation-mode/true?v=v2" width="561" height="230" role="button" title="WhatsApp Image 2024-03-13 at 17.19.05.jpeg" alt="WhatsApp Image 2024-03-13 at 17.19.05.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 16:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580646#M116274</guid>
      <dc:creator>ruiptoliveira</dc:creator>
      <dc:date>2024-03-16T16:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Having problems with TCP port allowance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580648#M116275</link>
      <description>&lt;P&gt;Hey Joerg,&lt;BR /&gt;Hope everything is okay with you and your family.&lt;BR /&gt;&lt;BR /&gt;I'm not sure if I understood your question, but I think I did.&lt;BR /&gt;I've internally tested the port for the local IPv4 (127.0.0.1) and it works just fine.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de ecrã 2024-03-16, às 16.30.05.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58432i7FB350F397CAF250/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Captura de ecrã 2024-03-16, às 16.30.05.png" alt="Captura de ecrã 2024-03-16, às 16.30.05.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 16:31:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-problems-with-tcp-port-allowance/m-p/580648#M116275</guid>
      <dc:creator>ruiptoliveira</dc:creator>
      <dc:date>2024-03-16T16:31:18Z</dc:date>
    </item>
  </channel>
</rss>

