<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Rules Log / Highlight Unused Rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6527#M4765</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the rule is been used atleast once, we cannot reset the counter unless a restart is done.&lt;/P&gt;&lt;P&gt;We can however change the name of the existing NAT/Policy rule ( "X" to "X-1"), This will again wait for a new packet to hit the rule, so that the "highlight unused" feature will work.&lt;/P&gt;&lt;P&gt;If it is a Rule constantly getting used(example Dynamic ISP NAT), it will be very hard to use the highlight unused feature. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Feb 2015 13:54:14 GMT</pubDate>
    <dc:creator>RajeshB</dc:creator>
    <dc:date>2015-02-24T13:54:14Z</dc:date>
    <item>
      <title>NAT Rules Log / Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6522#M4760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm doing maintenance and have doubts about a NAT rule.&lt;/P&gt;&lt;P&gt;I have enabled the "Highlight Unused Rules" and this rule seems to be that using currently. But we believe that this is not in use.&lt;/P&gt;&lt;P&gt;How can I see the activity related to a policy NAT?&lt;/P&gt;&lt;P&gt;How can I see that affects this rule?&lt;/P&gt;&lt;P&gt;How can I check the activity NAT using CLI?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2015 19:11:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6522#M4760</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-02-23T19:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Rules Log / Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6523#M4761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi CoS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check the sessions from CLI using the below command:&lt;/P&gt;&lt;P&gt;show session all filter nat-rule &amp;lt;rule-name&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To see what NAT rules are matched for a specific traffic you can also use the test command:&lt;/P&gt;&lt;P&gt;test nat-policy-match &amp;lt;criteria&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2015 21:31:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6523#M4761</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2015-02-23T21:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Rules Log / Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6524#M4762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks the "Highlight unused rule" option is working for Security Policy but not for the NAT policy on my PAN firewall. So, the CLI command mentioned by &lt;STRONG style="font-size: 11.6999998092651px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1246" data-externalid="" data-presence="null" data-userid="28201" data-username="bat" href="https://live.paloaltonetworks.com/people/bat" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;bat&lt;/A&gt;&lt;/STRONG&gt; would the right way to determine it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2015 22:19:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6524#M4762</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-02-23T22:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Rules Log / Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6525#M4763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find below the observed behavior:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added new NAT rules. Before commit, if iclick into the &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;"Highlight unused rule",&lt;/SPAN&gt; The feature works as expected. However, once commit is done in the PA, it is not highlighted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a BUG open for this: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Bug 65553 - After commit, Highlight Unused Rules does not wroks for NAT rules&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Resolved in:&lt;STRONG&gt;PAN OS 6.1.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2015 22:28:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6525#M4763</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-02-23T22:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Rules Log / Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6526#M4764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for letting us know the bug id and resolution version.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2015 00:31:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6526#M4764</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-02-24T00:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Rules Log / Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6527#M4765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the rule is been used atleast once, we cannot reset the counter unless a restart is done.&lt;/P&gt;&lt;P&gt;We can however change the name of the existing NAT/Policy rule ( "X" to "X-1"), This will again wait for a new packet to hit the rule, so that the "highlight unused" feature will work.&lt;/P&gt;&lt;P&gt;If it is a Rule constantly getting used(example Dynamic ISP NAT), it will be very hard to use the highlight unused feature. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2015 13:54:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6527#M4765</guid>
      <dc:creator>RajeshB</dc:creator>
      <dc:date>2015-02-24T13:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Rules Log / Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6528#M4766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also keep in mind that it will only highlight unused rules since the last reboot. But it sounds like the bug maybe causing it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2015 23:13:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-log-highlight-unused-rules/m-p/6528#M4766</guid>
      <dc:creator>oklier</dc:creator>
      <dc:date>2015-02-24T23:13:05Z</dc:date>
    </item>
  </channel>
</rss>

