<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Destination NAT not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208119#M60953</link>
    <description>&lt;P&gt;Question: If I am accepting SSL VPN clients on the same external interface/IP, does that cause issues for port forwarding?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Mar 2018 19:23:03 GMT</pubDate>
    <dc:creator>digitaltrance</dc:creator>
    <dc:date>2018-03-29T19:23:03Z</dc:date>
    <item>
      <title>Destination NAT not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208099#M60944</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having issues with my NAT config. I have everything from this doc completed but not seeing any traffic hit my outside interface in the logs.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/networking/nat/nat-configuration-examples/destination-nat-exampleone-to-many-mapping" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/networking/nat/nat-configuration-examples/destination-nat-exampleone-to-many-mapping&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I basically have a Synology NAS im trying to do port forwarding into from the outside.&lt;/P&gt;&lt;P&gt;I have a rule to log all blocked traffic from the external interface but not seeing anything hit the outside (is an easier way to see all blocked traffic without creating a rule for it?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did verify the Public IP address as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See screenshots for NAT, Policy configs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14552i1F38ACFA7067BC17/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT.PNG" alt="NAT.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14551iA206AB2DA992394E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="policy.PNG" alt="policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Charles&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:21:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208099#M60944</guid>
      <dc:creator>digitaltrance</dc:creator>
      <dc:date>2018-03-29T18:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208106#M60945</link>
      <description>&lt;P&gt;You can override the default deny rule to add logging, select it and hit the "orange and green" splat at the bottom of the screen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is your policy set to log at session start or session end?&amp;nbsp; if session end, it will nto log until a session ends (obviously) - you may see open sessions in the session browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming that 192.168.1 IP address is in the Internal-L3 zone, your policies look good to me.&amp;nbsp; Did this work previously, or is it a new configuration?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:30:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208106#M60945</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-03-29T18:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208107#M60946</link>
      <description>&lt;P&gt;Your config looks good, and it tripped me up a bit because my Synology NAS is also on 192.168.1.25.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure that your NAS has a route that takes it through the firewall. It can't just go through on any interface, it has to match the interface that sent the NAT external traffic to your NAS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can also try doing source NAT on your inbound NAT rule for the NAS as well. Set the source NAT to be the IP of the firewall's Internal-L3 interface.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:32:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208107#M60946</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-03-29T18:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208114#M60949</link>
      <description>&lt;P&gt;Thanks for the quick reply folks! I will try these and let you know.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:52:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208114#M60949</guid>
      <dc:creator>digitaltrance</dc:creator>
      <dc:date>2018-03-29T18:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208115#M60950</link>
      <description>&lt;P&gt;This is a new config.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:53:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208115#M60950</guid>
      <dc:creator>digitaltrance</dc:creator>
      <dc:date>2018-03-29T18:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208119#M60953</link>
      <description>&lt;P&gt;Question: If I am accepting SSL VPN clients on the same external interface/IP, does that cause issues for port forwarding?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 19:23:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208119#M60953</guid>
      <dc:creator>digitaltrance</dc:creator>
      <dc:date>2018-03-29T19:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208159#M60960</link>
      <description>&lt;P&gt;&lt;FONT color="#3366FF"&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Question: If I am accepting SSL VPN clients on the same external interface/IP, does that cause issues for port forwarding?&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only if it's on the same port. If your SSL VPN is using 443, it won't have any affect on any other ports (like 5001 or 22).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're trying to forward 443 though, something will break. The packet comes to the firewall only as a SYN on port 443, so the firewall won't know if it's destined for its own interface for GlobalProtect or if it should forward it to the server. It'll pick one, but I'm not sure which offhand.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 23:07:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-not-working/m-p/208159#M60960</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-03-29T23:07:08Z</dc:date>
    </item>
  </channel>
</rss>

