<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNAT issues into servers with teamed nic's ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156432#M51356</link>
    <description>&lt;P&gt;Not just SMTP.&lt;/P&gt;&lt;P&gt;Even RDP.&lt;/P&gt;&lt;P&gt;I notice in PAN logs it shows app as 'incomplete' and session end reason 'aged-out'.&lt;/P&gt;&lt;P&gt;But the successfull ones are app 'ms-rdp' and tcp states that are otherwise.&lt;/P&gt;&lt;P&gt;Like port '80' another DNAT, app parsed as 'activesync'... but.. also a ton of 'incompletes' .. which I can re-create by simply telnetting to port 80.. which would normally test my DNAT out.. but this deployment .. ages out.&lt;/P&gt;</description>
    <pubDate>Fri, 12 May 2017 16:36:11 GMT</pubDate>
    <dc:creator>mpgioia</dc:creator>
    <dc:date>2017-05-12T16:36:11Z</dc:date>
    <item>
      <title>DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156418#M51346</link>
      <description>&lt;P&gt;DNAT issues into servers with teamed nic's ?&lt;/P&gt;&lt;P&gt;Anyone seen issues with this before ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I literally can't DNAT into servers with teamed nic's..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm going to run a wireshark capture on the server to see what is going on..&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 14:56:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156418#M51346</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-12T14:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156419#M51347</link>
      <description>&lt;P&gt;Are servers virtual or physical boxes? Can you access resources&amp;nbsp;locally (without going through the Palo)?&lt;/P&gt;</description>
      <pubDate>Sun, 14 May 2017 19:07:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156419#M51347</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-14T19:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156420#M51348</link>
      <description>&lt;P&gt;Yes.. can hit the services on the servers fine inside...&lt;/P&gt;&lt;P&gt;Hyper-V.. quite sure.. don't have access to the underlying Hyper-V solution.. just the guest.. but can see Hyper-V NDIS bindings everywhere in the network settings so assume they are virtual and Hyper-V is the virt solution.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 15:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156420#M51348</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-12T15:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156422#M51349</link>
      <description>&lt;P&gt;The NAT's are getting to the server...&lt;/P&gt;&lt;P&gt;I can see it in wireshark on the endpoint..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's a mess of ip checksum mismatch's and ACK number mismatches..&lt;/P&gt;&lt;P&gt;Probably assymetry going on..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9238i7B339D670AD17A4A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 15:45:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156422#M51349</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-12T15:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156426#M51351</link>
      <description>&lt;P&gt;There.. Following a stream end to end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9239i1551AA7BF2190A46/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 15:51:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156426#M51351</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-12T15:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156427#M51352</link>
      <description>&lt;P&gt;&amp;nbsp;Traffic is getting from 10.1.0.17 to 14.202.123.242 (SYN), and 14.202.123.242 is replying (SYN-ACK)&amp;nbsp;but 10.1.0.17 isn't getting it. Is it getting blocked in the firewall?&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 16:09:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156427#M51352</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2017-05-12T16:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156428#M51353</link>
      <description>&lt;P&gt;Yes..&amp;nbsp; I was going to say that .. because client is sending SYN's again with seq=0 and never updating.&lt;/P&gt;&lt;P&gt;Checking...&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 16:10:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156428#M51353</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-12T16:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156429#M51354</link>
      <description>&lt;P&gt;Negative.&amp;nbsp; The inter-zone default block at the bottom is not popping up when over-ride and log is set.&lt;/P&gt;&lt;P&gt;And wireshark shows some streams getting to the SMTP EHLO.&amp;nbsp; So I know it gets through sometimes.&lt;/P&gt;&lt;P&gt;Also on PAN monitor it shows as tcp-fin for session end reason.. so I know it gets to the end of the tcp state-machine.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 16:23:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156429#M51354</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-12T16:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156432#M51356</link>
      <description>&lt;P&gt;Not just SMTP.&lt;/P&gt;&lt;P&gt;Even RDP.&lt;/P&gt;&lt;P&gt;I notice in PAN logs it shows app as 'incomplete' and session end reason 'aged-out'.&lt;/P&gt;&lt;P&gt;But the successfull ones are app 'ms-rdp' and tcp states that are otherwise.&lt;/P&gt;&lt;P&gt;Like port '80' another DNAT, app parsed as 'activesync'... but.. also a ton of 'incompletes' .. which I can re-create by simply telnetting to port 80.. which would normally test my DNAT out.. but this deployment .. ages out.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 16:36:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156432#M51356</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-12T16:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156433#M51357</link>
      <description>&lt;P&gt;I'm going to go on the basis the teamed setup on the NICs for the two servers i'm DNAT'ing to are creating session/state protocol hygiene disaster where PAN needs top notch hygiene (i.e. a cheap-ass NAT/router that was the routing/NAT point before the PAN port forwarded fine for these services).&lt;/P&gt;&lt;P&gt;Is there anything I can disable in terms of hygiene checks with assymetry for the TCP state machine on the PAN that will undeniably confirm/deny this is the issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also wireshark is spitting out ip checksum offload errors everywhere.. which may not be so much an issue as wireshark complains about this when packets have the whole hardware processing offload on the NIC for the checksum.&amp;nbsp; Guaranteed the servers with their broadcom software and NICs and team setup are doing this checksum offload.&lt;/P&gt;&lt;P&gt;But thought id just mention it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 16:47:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156433#M51357</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-12T16:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156437#M51358</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9240iC26DA5E22FFC66D8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 16:55:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156437#M51358</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-12T16:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156457#M51363</link>
      <description>&lt;P&gt;I did this.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Set-the-Palo-Alto-Networks-Firewall-to-Allow-non-Syn/ta-p/62868" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Set-the-Palo-Alto-Networks-Firewall-to-Allow-non-Syn/ta-p/62868&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Didn't make a difference. &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 17:50:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156457#M51363</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-12T17:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156556#M51406</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the first packet (SYN) traversed the firewall from the client side the session was created. Reply back from the server (SYN, ACK) will hit the same session on the&amp;nbsp;firewall and should get delivered to the client. Can&amp;nbsp;you please run a PCAP from the&amp;nbsp;client side as well as on the&amp;nbsp;Palo (creating filters so you only catching a relevant data). What we want to see is (SYN, ACK) hitting the client side as well as Palo sees ACK from the client.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 May 2017 09:37:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156556#M51406</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-14T09:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156557#M51407</link>
      <description>&lt;P&gt;Agreed... shall get it tomorrow.&lt;/P&gt;</description>
      <pubDate>Sun, 14 May 2017 09:39:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156557#M51407</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-14T09:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156576#M51413</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Are servers virtual or physical boxes? Can you access resources&amp;nbsp;locally (without going through the Palo)?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes.. so strangely.. I see a correlation.&lt;/P&gt;&lt;P&gt;2 x servers being Hyper-V hosts.&lt;/P&gt;&lt;P&gt;They can't have anything DNAT'd to them.&lt;/P&gt;&lt;P&gt;Guests that lie ontop of them are fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think it has anything to do with the teamed NICs.&lt;/P&gt;&lt;P&gt;I tore them down and still an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, can access resources from behind the firewall... all INSIDEis no issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some sort of protocol/packet/path hygiene, I can think of, is the only issue.&lt;/P&gt;&lt;P&gt;Swap the PAN for a standard perimeter NAT/router.. like a cheapy/small thing.&lt;/P&gt;&lt;P&gt;And it works fine.&amp;nbsp; Routing/NAT'ing through the PAN.&amp;nbsp; Equals blockages again.&lt;/P&gt;</description>
      <pubDate>Sun, 14 May 2017 23:38:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156576#M51413</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-14T23:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156579#M51414</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;@MicGioia wrote:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Are servers virtual or physical boxes? Can you access resources&amp;nbsp;locally (without going through the Palo)?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And interesting &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt; you asked whether the destination was virtual or physical.&lt;/P&gt;&lt;P&gt;Because that seems to be a correlation now.. Why did you ask that ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2017 00:28:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/156579#M51414</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-15T00:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/157002#M51538</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can not remember&amp;nbsp;why l did ask that. Maybe&amp;nbsp;just a random&amp;nbsp;thought &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; In any case, DNAT based on destination ip. As long as your server truly&amp;nbsp;holds that ip&amp;nbsp;connection should work. Did you figure out in the&amp;nbsp;end?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 20:44:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/157002#M51538</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-17T20:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/158416#M51837</link>
      <description>&lt;P&gt;* facepalm * l3 switch/routing concentration point had two default routes.. One pivoted one way another pivoted to inside of PAN.. ('another way' was the next hop of a prior device that the PAN is intending to replace..)....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything fine and good.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2017 04:21:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/158416#M51837</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-05-26T04:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT issues into servers with teamed nic's ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/158417#M51838</link>
      <description>&lt;P&gt;Well done!&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2017 06:36:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-issues-into-servers-with-teamed-nic-s/m-p/158417#M51838</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-26T06:36:51Z</dc:date>
    </item>
  </channel>
</rss>

