<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Test commnad on the nat policies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/test-commnad-on-the-nat-policies/m-p/39118#M28683</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did a quick test on PA-3020 and PA-200 and the test nat-policy-match command worked fine for me. I used PAN-OS 5.0.6 and 5.0.8. What PAN-OS version are you running? Perhaps you can try adding more parameters in your test command such as from zone, etc. See if that makes a difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Oct 2013 17:19:33 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-10-31T17:19:33Z</dc:date>
    <item>
      <title>Test commnad on the nat policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/test-commnad-on-the-nat-policies/m-p/39117#M28682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did an upgrade from a 500 model to a 3020 model. All the configurations work just fine. The problem that I see is that I cannot test the nat-policy rules. I have the following configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snat-all-LANs {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; from inside;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source [ 172.30.0.0/15 192.168.0.0/16 ];&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; to outside;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; to-interface&amp;nbsp; ;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service&amp;nbsp; any/any/any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate-to "src: #.#.#.# (dynamic-ip-and-port) (pool idx: 1)";&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; terminal no;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I do a test for the nat rule match it returns a no match result&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-3020-CE-01&amp;gt; test nat-policy-match&amp;nbsp; source 192.168.0.1 destination 8.8.8.8 destination-port 80 protocol 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No rule matched&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I find out why is there no match?&lt;/P&gt;&lt;P&gt;I have to mention that the NAT configuration works just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Costin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 15:02:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/test-commnad-on-the-nat-policies/m-p/39117#M28682</guid>
      <dc:creator>costin.gherghe</dc:creator>
      <dc:date>2013-10-31T15:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Test commnad on the nat policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/test-commnad-on-the-nat-policies/m-p/39118#M28683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did a quick test on PA-3020 and PA-200 and the test nat-policy-match command worked fine for me. I used PAN-OS 5.0.6 and 5.0.8. What PAN-OS version are you running? Perhaps you can try adding more parameters in your test command such as from zone, etc. See if that makes a difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 17:19:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/test-commnad-on-the-nat-policies/m-p/39118#M28683</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-31T17:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Test commnad on the nat policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/test-commnad-on-the-nat-policies/m-p/39119#M28684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have PAN-OS 5.0.6 installed on my device. I used for the test the source and destination zones and it identified the rule.&lt;/P&gt;&lt;P&gt;I also tested this on a 5050 with PAN-OS 5.0.3 and on this one the rule was identified by the "test nat-rule" without using zone parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any reason for this? (different OS?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Costin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 18:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/test-commnad-on-the-nat-policies/m-p/39119#M28684</guid>
      <dc:creator>costin.gherghe</dc:creator>
      <dc:date>2013-10-31T18:35:55Z</dc:date>
    </item>
  </channel>
</rss>

