<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Get Incomplete on Palo Alto after NAT on CheckPoint in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/get-incomplete-on-palo-alto-after-nat-on-checkpoint/m-p/6859#M5042</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;I need some help.&lt;/P&gt;&lt;P&gt;I I encoutered a problem with incomplete session during configuring a simple (as I thought) roule.&lt;/P&gt;&lt;P&gt;I have host inside my network and I want to configure the access from the internet. My configuration is: the first firewall is CheckPoint andthe second is Palo Alto.&lt;/P&gt;&lt;P&gt;I made a static NAT on it and proper rules to access to this host. Then I configured rules on Palo Alto. I did a simple rule that gives a right to access to this host but on internal IP (because according to me host is transalated later - on CheckPoint) on proper services.&lt;/P&gt;&lt;P&gt;Unfortunately there is only a incomplete sessions on Panorama logs.&lt;/P&gt;&lt;P&gt;Besides that I did proper routing entires both Palo Alto and CheckPoint machines.&lt;/P&gt;&lt;P&gt;I don't know what do I should configure more.&lt;/P&gt;&lt;P&gt;There are positive logs on checkpoint dashboard but there is no more information in Panorama logs about this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does aanyone of us can help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;By&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Dec 2010 21:05:09 GMT</pubDate>
    <dc:creator>pawel_serwatko</dc:creator>
    <dc:date>2010-12-09T21:05:09Z</dc:date>
    <item>
      <title>Get Incomplete on Palo Alto after NAT on CheckPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/get-incomplete-on-palo-alto-after-nat-on-checkpoint/m-p/6859#M5042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;I need some help.&lt;/P&gt;&lt;P&gt;I I encoutered a problem with incomplete session during configuring a simple (as I thought) roule.&lt;/P&gt;&lt;P&gt;I have host inside my network and I want to configure the access from the internet. My configuration is: the first firewall is CheckPoint andthe second is Palo Alto.&lt;/P&gt;&lt;P&gt;I made a static NAT on it and proper rules to access to this host. Then I configured rules on Palo Alto. I did a simple rule that gives a right to access to this host but on internal IP (because according to me host is transalated later - on CheckPoint) on proper services.&lt;/P&gt;&lt;P&gt;Unfortunately there is only a incomplete sessions on Panorama logs.&lt;/P&gt;&lt;P&gt;Besides that I did proper routing entires both Palo Alto and CheckPoint machines.&lt;/P&gt;&lt;P&gt;I don't know what do I should configure more.&lt;/P&gt;&lt;P&gt;There are positive logs on checkpoint dashboard but there is no more information in Panorama logs about this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does aanyone of us can help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;By&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 21:05:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/get-incomplete-on-palo-alto-after-nat-on-checkpoint/m-p/6859#M5042</guid>
      <dc:creator>pawel_serwatko</dc:creator>
      <dc:date>2010-12-09T21:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Get Incomplete on Palo Alto after NAT on CheckPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/get-incomplete-on-palo-alto-after-nat-on-checkpoint/m-p/6860#M5043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Try taking a look at the session trace on the incomplete session - that should give you some idea of how the packet is being seen by the PAN, what rules it's hitting, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A few questions for you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) how is the PAN deployed (l2, l3, vwire)?&amp;nbsp; &lt;/P&gt;&lt;P&gt;2) What does the policy on the PAN look like?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 01:35:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/get-incomplete-on-palo-alto-after-nat-on-checkpoint/m-p/6860#M5043</guid>
      <dc:creator>drogers</dc:creator>
      <dc:date>2010-12-10T01:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Get Incomplete on Palo Alto after NAT on CheckPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/get-incomplete-on-palo-alto-after-nat-on-checkpoint/m-p/6861#M5044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;An incomplete session means either the 3-way TCP handshake never completed or if it did complete there were no further packets.&amp;nbsp; This typically happens when the firewall only see's half of the traffic.&amp;nbsp; This can be due to asymmetric routing or perhaps a firewall rule/acl downstream from the Palo Alto firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you check the details of the session you will probably see only 1 packet was recorded which would also indicate that the firewall is not seeing the return traffic for some reason. (or maybe the return traffic is coming back on a different interface in another zone?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 06:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/get-incomplete-on-palo-alto-after-nat-on-checkpoint/m-p/6861#M5044</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-12-10T06:43:39Z</dc:date>
    </item>
  </channel>
</rss>

