<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 1-to-1 NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50274#M37017</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding one more information here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;Incomplete in the application field:&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Incomplete means that either the three way TCP handshake did NOT complete or the three way TCP handshake did complete but there was no data after the handshake to identify the application. In other words that traffic you are seeing is not really an application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;So to explain a little clearer, if a client sends a server a syn and the Palo Alto device creates a session for that syn, but the server never sends a SYN ACK in response back to the client, then that session would be seen as incomplete.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;FYI: KB article-&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1549"&gt;Incomplete, Insufficient data and Not-applicable in the application field&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Feb 2014 17:51:45 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-02-25T17:51:45Z</dc:date>
    <item>
      <title>1-to-1 NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50272#M37015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok need some help. I have a 1-to-1 NAT that is not working. Monitor-Traffic shows the Application as incomplete. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT Policy&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NAT Policy.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11760_NAT Policy.JPG.jpg" style="width: 620px; height: 26px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security Policy&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Security Policy.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11761_Security Policy.JPG.jpg" style="width: 620px; height: 25px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Monitor&lt;/P&gt;&lt;P&gt;&lt;IMG alt="monitor.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11765_monitor.JPG.jpg" style="width: 620px; height: 50px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Feb 2014 15:42:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50272#M37015</guid>
      <dc:creator>ddavis1</dc:creator>
      <dc:date>2014-02-25T15:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: 1-to-1 NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50273#M37016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per above screenshot, i hope you have configured Many-to-one Destination NAT. Could you please let me know, the address object "TEST PC RDP Private x.x.x). is a subnet or a single IP address...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please enable below mentioned option on traffic logs for better understanding:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="RDP.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11763_RDP.JPG.jpg" style="width: 620px; height: 402px;" /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Feb 2014 17:34:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50273#M37016</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-25T17:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: 1-to-1 NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50274#M37017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding one more information here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;Incomplete in the application field:&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Incomplete means that either the three way TCP handshake did NOT complete or the three way TCP handshake did complete but there was no data after the handshake to identify the application. In other words that traffic you are seeing is not really an application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;So to explain a little clearer, if a client sends a server a syn and the Palo Alto device creates a session for that syn, but the server never sends a SYN ACK in response back to the client, then that session would be seen as incomplete.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;FYI: KB article-&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1549"&gt;Incomplete, Insufficient data and Not-applicable in the application field&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Feb 2014 17:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50274#M37017</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-25T17:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: 1-to-1 NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50275#M37018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same issue as the OP. I hope someone has an answer. I'll keep an eye on this thread.&lt;/P&gt;&lt;P&gt;I don't know your configuration but I'm running a PA-VM on Esxi 5.5 with Promiscuous mode accepted on the vswitches in esxi. &lt;/P&gt;&lt;P&gt;Also tried PANOS 5.0.11 and PANOS 6.0 both has same results.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Feb 2014 19:04:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50275#M37018</guid>
      <dc:creator>StefanvanHattum</dc:creator>
      <dc:date>2014-02-28T19:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: 1-to-1 NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50276#M37019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to get mine to work. My issue was not paying attention. When i created the address object i put the correct IP in the description but fat-fingered that actual IP. So at a glance it looked correct. Below are some pics of my working 1-to-1 NAT. If you click the image it will enlarge. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT:&lt;BR /&gt;&lt;IMG alt="NAT.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11819_NAT.JPG.jpg" style="width: 620px; height: 26px;" /&gt;&lt;/P&gt;&lt;P&gt;Security:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Security.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11820_Security.JPG.jpg" style="width: 620px; height: 26px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Feb 2014 19:18:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50276#M37019</guid>
      <dc:creator>ddavis1</dc:creator>
      <dc:date>2014-02-28T19:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: 1-to-1 NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50277#M37020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope this helps. I know some may look odd where you see destination as WAN but i did verify with my PA rep that it is correct. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NAT Original Tab.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11821_NAT Original Tab.JPG.jpg" style="width: 620px; height: 342px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NAT Translated Tab.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11822_NAT Translated Tab.JPG.jpg" style="width: 620px; height: 212px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security Policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Security Source Tab.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11823_Security Source Tab.JPG.jpg" style="width: 620px; height: 358px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Security Destination Tab.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11824_Security Destination Tab.JPG.jpg" style="width: 620px; height: 358px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Security Application Tab.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11825_Security Application Tab.JPG.jpg" style="width: 620px; height: 335px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Feb 2014 19:28:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50277#M37020</guid>
      <dc:creator>ddavis1</dc:creator>
      <dc:date>2014-02-28T19:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: 1-to-1 NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50278#M37021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry forgot one image&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Security Service Tab.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11826_Security Service Tab.JPG.jpg" style="width: 620px; height: 338px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Feb 2014 19:30:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50278#M37021</guid>
      <dc:creator>ddavis1</dc:creator>
      <dc:date>2014-02-28T19:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: 1-to-1 NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50279#M37022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had the NAT and security policy already setup exactly the same way, according to the student books &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;Also checked the objects and the ip-addresses all are good.&lt;/P&gt;&lt;P&gt;I have even added an extra NIC to the ESXi server and set the eth1/2 port to the new interface (promiscuous mode accept) so that the management interface and the data interface eth1/2 are on seperate nics but the same LAN.&lt;/P&gt;&lt;P&gt;But it still gives an incomplete.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="11884" alt="incomplete.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11884_incomplete.jpg" style="width: 620px; height: 52px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has something to do with the PA, because I have a PFSense firewall running on a different external IP address and the static NAT rules on that are working perfect.&lt;/P&gt;&lt;P&gt;I was planning to replace my PFSense for the VM-PA also to get some more hand-on experience as we are placing some PA's in the network at my work, but if I don't get the NAT working then I'll stick to PFsense.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Mar 2014 16:57:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50279#M37022</guid>
      <dc:creator>StefanvanHattum</dc:creator>
      <dc:date>2014-03-01T16:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: 1-to-1 NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50280#M37023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="21412" data-username="StefanvanHattum" href="https://live.paloaltonetworks.com/people/StefanvanHattum" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;StefanvanHattum&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ,&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you are facing any problem with your PA-VM and could not identify the root cause of the issue, please open a ticket with PAN support and &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;let&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; us know what a good time would be to get together and continue to work on the network. Our number one priority is to ensure that everything is running smoothly at &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;your&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; site, and, &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;minimize&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; any business impact, the problem caused.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Mar 2014 02:53:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50280#M37023</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-03-02T02:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: 1-to-1 NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50281#M37024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;&lt;P&gt;I ahve created a case at support.&lt;/P&gt;&lt;P&gt;Mind you that this is not impacting any business, this is just a test setup at home for learning purposes.&lt;/P&gt;&lt;P&gt;And I was planning to replace my PFSense, but I don't think I'm going to do that as there is no good way to get Xbox live to work &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stefan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Mar 2014 17:18:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-to-1-nat/m-p/50281#M37024</guid>
      <dc:creator>Tjempeng</dc:creator>
      <dc:date>2014-03-02T17:18:55Z</dc:date>
    </item>
  </channel>
</rss>

