<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dropped Traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159757#M52158</link>
    <description>&lt;P&gt;This is screen shot from the NAT Policy screen .&lt;/P&gt;&lt;P&gt;There is alos another NAT policy the other way for this IP , so we do have a bi-directionl NAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this NAT policy not imply that all traffic comeing into this IP is NAted to internal IP&lt;/P&gt;&lt;P&gt;I only have a rule to allow public ip , ext zone &amp;gt; my public ip ext zone for ipsec and IKE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is being denied by my Deny All rule , I assume becasue the FW is only seeing the NAted destination (internal) becasue NAT is done before the FW Rules are hit ?&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jun 2017 15:13:00 GMT</pubDate>
    <dc:creator>RC-BHF</dc:creator>
    <dc:date>2017-06-06T15:13:00Z</dc:date>
    <item>
      <title>Dropped Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159710#M52150</link>
      <description>&lt;P&gt;We have PA3000 running 7.1.10&lt;/P&gt;&lt;P&gt;I have issue where tarffic is being droped by the Deny All rule , the last rule even though I have allowed this tarffic to come in ext zone ext zone.&lt;/P&gt;&lt;P&gt;Also for some reason the destination seems to be Internal where as the interafce is the public one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does any one have an explanation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9541iFE6794CEE159D7C1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 13:54:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159710#M52150</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2017-06-06T13:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159718#M52152</link>
      <description>&lt;P&gt;Check if you accidentally apply NAT to traffic that hits your public IP 212.240.x.x port 500.&lt;/P&gt;&lt;P&gt;Maybe you have one-to-one NAT to some internal IP.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 14:03:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159718#M52152</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-06-06T14:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159729#M52153</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I do have the follwing NAT on the public IP . Is the any service the&amp;nbsp; issue ? The transalated packet goes to a internal host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9542iDF765455BD7BC0FF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 14:24:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159729#M52153</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2017-06-06T14:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159755#M52156</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/32033"&gt;@RC-BHF&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The any service wouldn't really be an issue. Maybe take a screenshot of the actual policy in the NAT policy screen instead of this section. If you have the NAT configured bi-directional: yes then you could potentially see exactly what you are describing, as the destination interface then would come across as whatever zone that original source address actually resides in.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 14:52:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159755#M52156</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-06T14:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159757#M52158</link>
      <description>&lt;P&gt;This is screen shot from the NAT Policy screen .&lt;/P&gt;&lt;P&gt;There is alos another NAT policy the other way for this IP , so we do have a bi-directionl NAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this NAT policy not imply that all traffic comeing into this IP is NAted to internal IP&lt;/P&gt;&lt;P&gt;I only have a rule to allow public ip , ext zone &amp;gt; my public ip ext zone for ipsec and IKE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is being denied by my Deny All rule , I assume becasue the FW is only seeing the NAted destination (internal) becasue NAT is done before the FW Rules are hit ?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 15:13:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159757#M52158</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2017-06-06T15:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159816#M52165</link>
      <description>&lt;P&gt;Wait so you have two NAT policies instead of just one bi-directional policy. That seems like you could easily make this a small amount easier to manage at the very least.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes that would be correct, you would want to modify that security policy to show whatever zone you are actually sending that traffic to. For example since everything public facing is in the DMZ zone I have to have security policies that have the destination zone being DMZ with the destination IP being whatever public IP the NAT associates with.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 17:05:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159816#M52165</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-06T17:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159818#M52166</link>
      <description>&lt;P&gt;Yes this rule is the isue.&lt;/P&gt;&lt;P&gt;If you need only limited ports to NAT to internal host then change service Any to tcp/80 or whatever port you need.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or clone this NAT rule.&lt;/P&gt;&lt;P&gt;Move clone rule above it.&lt;/P&gt;&lt;P&gt;Change cloned rule to add service udp/500 and clear out&amp;nbsp;Destination Address Translation under "Translated Packet" tab.&lt;/P&gt;&lt;P&gt;This will exclude incoming IPSec from DNAT.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 17:14:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159818#M52166</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-06-06T17:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159853#M52176</link>
      <description>&lt;P&gt;Well done all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue seems with NAT policy:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9546i411938163231D051/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA.png" alt="PA.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;has already mentioned DNAT exempt&amp;nbsp;is needed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 18:26:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dropped-traffic/m-p/159853#M52176</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-06T18:26:29Z</dc:date>
    </item>
  </channel>
</rss>

