<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wildfire Alert reporting source and destination NATs that aren't configured on associated firewalls in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-alert-reporting-source-and-destination-nats-that-aren-t/m-p/127961#M46626</link>
    <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've had several Wildfire Alerts that show both the source and destination addresses translated yet NAT is not configured.&amp;nbsp; For the subject data flow, the source is an external network for which we have no control.&amp;nbsp; The destination is our client.&amp;nbsp; The Alert shows that that the Source address is being translated to another address that is not under our control.&amp;nbsp; The destination address is shown as being translated to our firewall's address.&amp;nbsp; NAT is not configured for either situation in our PA firewalls.&amp;nbsp; Any ideas?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 21 Nov 2016 23:03:24 GMT</pubDate>
    <dc:creator>jstcolorado</dc:creator>
    <dc:date>2016-11-21T23:03:24Z</dc:date>
    <item>
      <title>Wildfire Alert reporting source and destination NATs that aren't configured on associated firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-alert-reporting-source-and-destination-nats-that-aren-t/m-p/127961#M46626</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've had several Wildfire Alerts that show both the source and destination addresses translated yet NAT is not configured.&amp;nbsp; For the subject data flow, the source is an external network for which we have no control.&amp;nbsp; The destination is our client.&amp;nbsp; The Alert shows that that the Source address is being translated to another address that is not under our control.&amp;nbsp; The destination address is shown as being translated to our firewall's address.&amp;nbsp; NAT is not configured for either situation in our PA firewalls.&amp;nbsp; Any ideas?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2016 23:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-alert-reporting-source-and-destination-nats-that-aren-t/m-p/127961#M46626</guid>
      <dc:creator>jstcolorado</dc:creator>
      <dc:date>2016-11-21T23:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Alert reporting source and destination NATs that aren't configured on associated firewa</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-alert-reporting-source-and-destination-nats-that-aren-t/m-p/128017#M46630</link>
      <description>&lt;P&gt;Check the ports.&amp;nbsp;TCP connection was probably in the other direction; from client to internet for which you have destination (hide) NAT. Like normal web browsing session goes.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 07:04:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-alert-reporting-source-and-destination-nats-that-aren-t/m-p/128017#M46630</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-11-22T07:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Alert reporting source and destination NATs that aren't configured on associated firewa</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-alert-reporting-source-and-destination-nats-that-aren-t/m-p/128198#M46661</link>
      <description>&lt;P&gt;The flow started with out client connecting via TCP 80 to an external web server.&amp;nbsp; The web server, in return, downloaded software to our client.&amp;nbsp; This thread is focused&amp;nbsp; on the server to client communication - Server [TCP-80] to client [61905].&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The server IP is shown in the Wildfire Threat alert as being translated to another external IP.&amp;nbsp; The client is being shown as being translated to our&amp;nbsp;firewalls IP.&amp;nbsp; What's interesting is that the client IP is also seen in PCAPs going to other Internet sites without address translation and we've&amp;nbsp; verified that we have&amp;nbsp;no firewall configurations to translate the client IP.&amp;nbsp; The server IP was also seen in another Wildfire Threat Alert and the Alert specifies that it was translated to yet another address.&amp;nbsp; Here are the threat alerts that show the server IP being tranlated to two different addresses.&amp;nbsp; Note that I used ficticious addresses for the purpose of this exampbe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Threat Allert #1: medium:&amp;nbsp;1.1.1.1 -&amp;gt;2.2.2.2 Windows Executable&lt;/P&gt;&lt;P&gt;subtype: wildfire&lt;/P&gt;&lt;P&gt;category: malicious&lt;/P&gt;&lt;P&gt;direction: server-to-client&lt;/P&gt;&lt;P&gt;src: 1.1.1.1 (remote server)&lt;/P&gt;&lt;P&gt;dst: 2.2.2.2 (our client)&lt;/P&gt;&lt;P&gt;natsrc: 3.3.3.3 (??????)&lt;/P&gt;&lt;P&gt;natdst: 4.4.4.4 (Local PA firewall IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Threat Alert #2: medium: 1.1.1.1 -&amp;gt; 2.2.2.2 Windows Executable&lt;/P&gt;&lt;P&gt;subtype: wildfire&lt;/P&gt;&lt;P&gt;category: malicious&lt;/P&gt;&lt;P&gt;direction: server-to-client&lt;/P&gt;&lt;P&gt;src: 1.1.1.1 (same remote server)&lt;/P&gt;&lt;P&gt;dst: 2.2.2.2 (same client)&lt;/P&gt;&lt;P&gt;natsrc: 5.5.5.5 (server translated to a differnet IP this time)&lt;/P&gt;&lt;P&gt;natdst: 4.4.4.4 (Local PA firewall IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 15:55:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-alert-reporting-source-and-destination-nats-that-aren-t/m-p/128198#M46661</guid>
      <dc:creator>jstcolorado</dc:creator>
      <dc:date>2016-11-22T15:55:31Z</dc:date>
    </item>
  </channel>
</rss>

