<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Destination NAT translation is not working  os .5.0.10 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6384#M4649</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/27418"&gt;Satish&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you confirm if the traffic for that IP address is even reaching the firewall ? Try configuring packet capture and see if the packet is reaching the firewall, if it's not then it should be a simple ARP or routing issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Jan 2015 20:55:09 GMT</pubDate>
    <dc:creator>bat</dc:creator>
    <dc:date>2015-01-09T20:55:09Z</dc:date>
    <item>
      <title>Destination NAT translation is not working  os .5.0.10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6379#M4644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAN OS 5.0.10 is running. i have create a destination NAT translation but is not working and also i am not getting any logs. please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG alt="gts.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17624_gts.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NAT.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17625_NAT.png" style="height: 265px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jan 2015 11:15:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6379#M4644</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2015-01-09T11:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT translation is not working  os .5.0.10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6380#M4645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a security policy for this traffic with activated logging?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jan 2015 11:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6380#M4645</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2015-01-09T11:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT translation is not working  os .5.0.10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6381#M4646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Wenar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I have already a security policy for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jan 2015 11:38:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6381#M4646</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2015-01-09T11:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT translation is not working  os .5.0.10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6382#M4647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post a screenshot of the security policy? Keep in mind that your security policy has to look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source:Any&lt;/P&gt;&lt;P&gt;Source Zone: Any (or Untrust)&lt;/P&gt;&lt;P&gt;Destination: Public IP&lt;/P&gt;&lt;P&gt;Destination Zone: Zone for Private IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see the traffic in the traffic log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jan 2015 13:24:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6382#M4647</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2015-01-09T13:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT translation is not working  os .5.0.10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6383#M4648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify your Security Policy and NAT policy look like what you see below. Make sure that Destination address for your NAT and Security Policy is your Public IP.&lt;/P&gt;&lt;P&gt;Also, for your NAT policy use Source Zone: Untrust, Destination Zone: Untrust. Use only Private IP in your Translated Destination Address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security Policy&lt;/P&gt;&lt;P&gt;&lt;IMG alt="SecurityPolicy.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17628_SecurityPolicy.JPG" style="height: 30px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nat policy&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="17627" alt="NATPolicy.JPG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17627_NATPolicy.JPG" style="height: 38px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jan 2015 16:40:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6383#M4648</guid>
      <dc:creator>rborda</dc:creator>
      <dc:date>2015-01-09T16:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT translation is not working  os .5.0.10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6384#M4649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/27418"&gt;Satish&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you confirm if the traffic for that IP address is even reaching the firewall ? Try configuring packet capture and see if the packet is reaching the firewall, if it's not then it should be a simple ARP or routing issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jan 2015 20:55:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6384#M4649</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2015-01-09T20:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT translation is not working  os .5.0.10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6385#M4650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hurricane electric has a helpful public looking glass utility: &lt;A href="http://lg.he.net/" title="http://lg.he.net/"&gt;Looking Glass - Hurricane Electric (AS6939)&lt;/A&gt;. They even have an app for the Android &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jan 2015 22:13:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6385#M4650</guid>
      <dc:creator>oklier</dc:creator>
      <dc:date>2015-01-09T22:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT translation is not working  os .5.0.10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6386#M4651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would start by filtering your policy logs by the source address of the attempt.&amp;nbsp; Then you can see what policy the traffic is hitting in your firewall.&amp;nbsp; Make sure you do have a logging final deny all policy so it is not silently dropped and that logging is enabled for all policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nat columns can be added to the monitor policy logs so you will also see from here if the traffic is being recognized by any of the nat rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Jan 2015 13:38:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6386#M4651</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-01-10T13:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT translation is not working  os .5.0.10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6387#M4652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to add something that has not been mentioned... It could be possible that the traffic is indeed reaching the firewall and the NAT itself working properly, but you need to make sure you have a route not only on the firewall to reach the private IP, but also a route configured on the server itself to get back to the outside world through the same firewall interface that was used to forward the incoming packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Jan 2015 14:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-translation-is-not-working-os-5-0-10/m-p/6387#M4652</guid>
      <dc:creator>parmas</dc:creator>
      <dc:date>2015-01-10T14:13:59Z</dc:date>
    </item>
  </channel>
</rss>

