<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port Forwarding Problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169137#M53774</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69996"&gt;@RJSCSLLC&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The following might help you a little bit more than what you found in the above article. I would look at live prior to following a random article; usually you'll find we include more information and pictures &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The entire article this was pulled from can be found &lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/networking/nat-configuration-examples#_59262" target="_blank"&gt;HERE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="xml parbase xml_level-3_26"&gt;&lt;DIV class="level-3"&gt;Destination NAT with Port Translation Example&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_body_27"&gt;&lt;DIV class="body"&gt;In this example, the web server is configured to listen for HTTP traffic on port 8080. The clients access the web server using the IP address 1.1.1.100 and TCP Port 80. The destination NAT rule is configured to translate both IP address and port to 10.1.1.100 and TCP port 8080.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml_anchor_28 xml parbase"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_DIV_29"&gt;&lt;DIV class="DIV"&gt;&lt;DIV&gt;&lt;IMG src="https://ip1.i.lithium.com/fde71ad3c3c4cf3940dd38f24a4bb8f585058c6f/68747470733a2f2f7777772e70616c6f616c746f6e6574776f726b732e636f6d2f6574632f6672616d656d616b65722f37302f70616e2d6f732f70616e2d6f732d61646d696e2f7870616e2d6f732d3832362e6769662e7061676573706565642e69632e33353432766c37496e6d2e77656270" border="0" /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_body_30"&gt;&lt;DIV class="body"&gt;The following NAT and security rules must be configured on the firewall:&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_anchor_31"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="xml_DIV_32 xml parbase"&gt;&lt;DIV class="DIV"&gt;&lt;DIV&gt;&lt;IMG src="https://ip1.i.lithium.com/a096d0b326ff22fba92aad317c592bd584ca1509/68747470733a2f2f7777772e70616c6f616c746f6e6574776f726b732e636f6d2f6574632f6672616d656d616b65722f37302f70616e2d6f732f70616e2d6f732d61646d696e2f7870616e2d6f732d3832372e6769662e7061676573706565642e69632e787971313359496e68552e77656270" border="0" /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_anchor_33"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="xml_DIV_34 xml parbase"&gt;&lt;DIV class="DIV"&gt;&lt;DIV&gt;&lt;IMG src="https://ip1.i.lithium.com/12977a6838896be86fb3858d91053d396949b513/68747470733a2f2f7777772e70616c6f616c746f6e6574776f726b732e636f6d2f6574632f6672616d656d616b65722f37302f70616e2d6f732f70616e2d6f732d61646d696e2f7870616e2d6f732d3832382e6769662e7061676573706565642e69632e3777486f5f7434556a442e77656270" border="0" /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_body_35"&gt;&lt;DIV class="body"&gt;Use the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;show session all&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;CLI command to verify the translation.&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 31 Jul 2017 20:21:12 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-07-31T20:21:12Z</dc:date>
    <item>
      <title>Port Forwarding Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169086#M53766</link>
      <description>&lt;P&gt;This should be fairly simple but am at wits end. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to forward 2 ports from an external IP to an internal private ip (Ports 8088 and 22). &amp;nbsp;I found this article and am following its example: &amp;nbsp;&lt;A href="https://nubisnovem.com/pinning-a-hole-in-palo-alto/" target="_blank"&gt;https://nubisnovem.com/pinning-a-hole-in-palo-alto/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Public/Outside IP of PA-220 : 44.44.44.44&lt;/P&gt;&lt;P&gt;Internal IP: 192.168.0.222&lt;/P&gt;&lt;P&gt;IP I am trying to browse/connect from: 123.123.2.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created two Services&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name: 8088&lt;/P&gt;&lt;P&gt;Protocol: TCP&lt;/P&gt;&lt;P&gt;Destination Port: 8088&lt;/P&gt;&lt;P&gt;Source Port: 1-65535&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name: SSH&lt;/P&gt;&lt;P&gt;Protocol: TCP&lt;/P&gt;&lt;P&gt;Desitnation Port: 22&lt;/P&gt;&lt;P&gt;Source Port: 1-65535&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created two NAT statements&lt;/P&gt;&lt;P&gt;Name: 8088&lt;/P&gt;&lt;P&gt;Source Zone: Outside&lt;/P&gt;&lt;P&gt;Destination Zone: Outside&lt;/P&gt;&lt;P&gt;Destination Interface: Any&lt;/P&gt;&lt;P&gt;Source Address: Any&lt;/P&gt;&lt;P&gt;Destination Address: 44.44.44.44&lt;/P&gt;&lt;P&gt;Service: 8088&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source Translation: None&lt;/P&gt;&lt;P&gt;Destination Translation:&amp;nbsp;&lt;SPAN&gt;192.168.0.222&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name:&amp;nbsp;22&lt;/P&gt;&lt;P&gt;Source Zone: Outside&lt;/P&gt;&lt;P&gt;Destination Zone: Outside&lt;/P&gt;&lt;P&gt;Destination Interface: Any&lt;/P&gt;&lt;P&gt;Source Address: Any&lt;/P&gt;&lt;P&gt;Destination Address: 44.44.44.44&lt;/P&gt;&lt;P&gt;Service:&amp;nbsp;22&lt;/P&gt;&lt;P&gt;Source Translation: None&lt;/P&gt;&lt;P&gt;Destination Translation:&amp;nbsp;&lt;SPAN&gt;192.168.0.222&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I also created 1 security policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Name: PortForward&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Source Zone: Outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Source Address: Any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Destination Zone: Inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Destination Address: 192.168.0.222&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Application: Any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Service: 8088 and 22&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Action: Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I browse through a webpage to 44.44.44.44:8088 a web browser. &amp;nbsp;PA Monitor shows incomplete under application&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA2.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10565iAF6CAFFEAB9EBF0F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA2.PNG" alt="PA2.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Log Detail:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA1.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10567i63C69E2D63EC48B0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA1.PNG" alt="PA1.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Like I said I am basing everything on the article above so there may be a better way to do it. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any advice is appreciated.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 16:32:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169086#M53766</guid>
      <dc:creator>RJSCSLLC</dc:creator>
      <dc:date>2017-07-31T16:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169094#M53768</link>
      <description>&lt;P&gt;Most likely,&amp;nbsp;&lt;SPAN&gt;192.168.0.222 doesn't have a route back to&amp;nbsp;123.123.2.2, or else it's using a different egress point.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A couple things you can do:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Make sure that 192.168.0.222 has a route to 123.123.2.2 and that it goes through the Palo Alto Networks firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. Use source NAT in addition, specifying the internal IP of the firewall.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Your traffic log detail shows it just barely, 0 bytes and packets received with 62 bytes sent, probably the TCP SYN packet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Greg Wesson&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 16:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169094#M53768</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-07-31T16:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169096#M53769</link>
      <description>&lt;P&gt;Greg,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Appreciate your response. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I have an additional NAT from my internal zone to external its basically my NAT for internet access from my inside zone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name: &amp;nbsp;Inside - Internet Access&lt;/P&gt;&lt;P&gt;Source Zone: Inside&lt;/P&gt;&lt;P&gt;Destination Zone: Outside&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source Address: &amp;nbsp;192.168.0.0/24&lt;/P&gt;&lt;P&gt;Source Translation: dynamic ip and port &amp;nbsp; - 44.44.44.44&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That should suffice from getting back to 123.123.2.2 shouldn't it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Do I need the source NAT if I already have the above NAT? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Again, thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 16:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169096#M53769</guid>
      <dc:creator>RJSCSLLC</dc:creator>
      <dc:date>2017-07-31T16:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169099#M53770</link>
      <description>&lt;P&gt;There is only one NAT rule that is applied for each session, so the separate Source NAT rule you provided won't get applied when the other one is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming L3 setup:&lt;/P&gt;&lt;P&gt;Run a traceroute from the internal server to the external client IP. Make sure that the MAC address of the firewall your server hits is the same one that is sourcing the traffic inbound from that external client. If not, you've got a routing issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're familiar with packet captures, you can take one on the firewall (grab&amp;nbsp;&lt;STRONG&gt;transmit&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;receive&lt;/STRONG&gt; stages) at the same time as one running on the internal server. You should be able to confirm if the SYN is making it to the server, if the server is responding with the expected SYN+ACK, and if that's making it back to the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Greg&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 17:20:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169099#M53770</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-07-31T17:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169137#M53774</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69996"&gt;@RJSCSLLC&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The following might help you a little bit more than what you found in the above article. I would look at live prior to following a random article; usually you'll find we include more information and pictures &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The entire article this was pulled from can be found &lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/networking/nat-configuration-examples#_59262" target="_blank"&gt;HERE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="xml parbase xml_level-3_26"&gt;&lt;DIV class="level-3"&gt;Destination NAT with Port Translation Example&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_body_27"&gt;&lt;DIV class="body"&gt;In this example, the web server is configured to listen for HTTP traffic on port 8080. The clients access the web server using the IP address 1.1.1.100 and TCP Port 80. The destination NAT rule is configured to translate both IP address and port to 10.1.1.100 and TCP port 8080.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml_anchor_28 xml parbase"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_DIV_29"&gt;&lt;DIV class="DIV"&gt;&lt;DIV&gt;&lt;IMG src="https://ip1.i.lithium.com/fde71ad3c3c4cf3940dd38f24a4bb8f585058c6f/68747470733a2f2f7777772e70616c6f616c746f6e6574776f726b732e636f6d2f6574632f6672616d656d616b65722f37302f70616e2d6f732f70616e2d6f732d61646d696e2f7870616e2d6f732d3832362e6769662e7061676573706565642e69632e33353432766c37496e6d2e77656270" border="0" /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_body_30"&gt;&lt;DIV class="body"&gt;The following NAT and security rules must be configured on the firewall:&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_anchor_31"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="xml_DIV_32 xml parbase"&gt;&lt;DIV class="DIV"&gt;&lt;DIV&gt;&lt;IMG src="https://ip1.i.lithium.com/a096d0b326ff22fba92aad317c592bd584ca1509/68747470733a2f2f7777772e70616c6f616c746f6e6574776f726b732e636f6d2f6574632f6672616d656d616b65722f37302f70616e2d6f732f70616e2d6f732d61646d696e2f7870616e2d6f732d3832372e6769662e7061676573706565642e69632e787971313359496e68552e77656270" border="0" /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_anchor_33"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="xml_DIV_34 xml parbase"&gt;&lt;DIV class="DIV"&gt;&lt;DIV&gt;&lt;IMG src="https://ip1.i.lithium.com/12977a6838896be86fb3858d91053d396949b513/68747470733a2f2f7777772e70616c6f616c746f6e6574776f726b732e636f6d2f6574632f6672616d656d616b65722f37302f70616e2d6f732f70616e2d6f732d61646d696e2f7870616e2d6f732d3832382e6769662e7061676573706565642e69632e3777486f5f7434556a442e77656270" border="0" /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="xml parbase xml_body_35"&gt;&lt;DIV class="body"&gt;Use the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;show session all&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;CLI command to verify the translation.&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 31 Jul 2017 20:21:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169137#M53774</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-31T20:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169216#M53784</link>
      <description>&lt;P&gt;Ok. &amp;nbsp;So I am still not having any luck. &amp;nbsp;For troubleshooting purposes. I installed IIS on an inside PC on the same network and set up an additional NAT for http-web browsing that works fine but still can not get port 8088 to work at all. Below Rule 1 works fine Rule 2 does not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="test80.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10579i55CE242993C48766/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="test80.PNG" alt="test80.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="http.PNG" style="width: 723px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10585iCA957BFF5DED70F5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="http.PNG" alt="http.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8088.PNG" style="width: 719px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10586iE60561707AF0FA6E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="8088.PNG" alt="8088.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point for testing purposes I just have a permit any security policy&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="any.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10580i9371FB70F4C3022B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="any.PNG" alt="any.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is interesting is in the monitor log the application shows as application web-browsing for when I go to port 80 and it works but it still shows as incomplete when trying 8088&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="permit.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10583i52A3C0DDD5EA1FFA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="permit.PNG" alt="permit.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="notworking.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10584i59787AECD9A665E1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="notworking.PNG" alt="notworking.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So to sum up. &amp;nbsp;I have a wide open security policy, 2 identical NAT statements in which the service set up is exactly the same, one for port 80 and one for port 8088. &amp;nbsp;Port 80 works fine going to 192.168.0.45 but port 8088 going to 192.168.0.222 does not. &amp;nbsp;If I get on an internal PC and browse to 192.168.0.222:8088 it works just fine so I am pretty certain there isn't an internal PC firewall blocking anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;browsing to publiciip:80 works like it should but publicip:8088 does not. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure how else to troubleshoot.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks again for any suggestions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 05:56:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169216#M53784</guid>
      <dc:creator>RJSCSLLC</dc:creator>
      <dc:date>2017-08-01T05:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169308#M53810</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69996"&gt;@RJSCSLLC&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you PCAP the traffic what exactly do you see. Your NAT appears to be working otherwise you wouldn't get the log, so you either don't have a return path properly setup for the traffic or the 192.168.0.222 is not setup properly so you never get a response.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 15:31:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-problem/m-p/169308#M53810</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-01T15:31:47Z</dc:date>
    </item>
  </channel>
</rss>

