<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Xbox Live with dynamic public IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8491#M6272</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This would be a destination NAT correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Jun 2014 17:00:46 GMT</pubDate>
    <dc:creator>swoods79</dc:creator>
    <dc:date>2014-06-30T17:00:46Z</dc:date>
    <item>
      <title>Xbox Live with dynamic public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8485#M6266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know that this topic has been discussed before, but I cannot seem to find an exact scenario match since I am dealing with a dynamic public IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Interfaces&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ethernet1/1&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Primary internal network&lt;/LI&gt;&lt;LI&gt;Default virtual router&lt;/LI&gt;&lt;LI&gt;172.16.50.1/24&lt;/LI&gt;&lt;LI&gt;Zone: Internal&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;ethernet1/2&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Public internet connection with dynamic IP address&lt;/LI&gt;&lt;LI&gt;Default virtual router&lt;/LI&gt;&lt;LI&gt;Zone: External&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;ethernet1/3&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Secondary internal network dedicated to Xbox&lt;/LI&gt;&lt;LI&gt;Default virtual router&lt;/LI&gt;&lt;LI&gt;172.16.51.1/24&lt;/LI&gt;&lt;LI&gt;Zone: Xbox&lt;/LI&gt;&lt;LI&gt;DHCP reservation in place for the Xbox at 172.16.51.2&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security Policies&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule to allow traffic from Internal and Xbox zones to External zone.&lt;UL&gt;&lt;LI&gt;Includes URL filtering, etc.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Rule to deny all other traffic.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NAT Policies&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Single NAT policy defined as follows:&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;Original Packet&lt;/EM&gt;&lt;UL&gt;&lt;LI&gt;Source Zone: Internal, Xbox&lt;/LI&gt;&lt;LI&gt;Destination Zone: External&lt;/LI&gt;&lt;LI&gt;Destination Interface: ethernet1/2&lt;/LI&gt;&lt;LI&gt;Service: any&lt;/LI&gt;&lt;LI&gt;Source Address: any&lt;/LI&gt;&lt;LI&gt;Destination Address: any&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Translation Packet&lt;/EM&gt;&lt;UL&gt;&lt;LI&gt;Translation Type: Dynamic IP and Port&lt;/LI&gt;&lt;LI&gt;Address Type: Interface Address&lt;/LI&gt;&lt;LI&gt;Interface: ethernet1/2&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Internal and Xbox zones are able to browse the Internet without any issues; however, the Xbox reports the NAT type as Strict which causes Xbox Live to not function properly.&amp;nbsp; Given the fact that I have only a single public IP address for all traffic (which is also dynamic and not static), how do I go about allowing the necessary ports through to the Xbox?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ports in question: &lt;A href="http://support.xbox.com/en-US/xbox-360/networking/network-ports-used-xbox-live" title="http://support.xbox.com/en-US/xbox-360/networking/network-ports-used-xbox-live"&gt;Xbox Network Ports | Xbox 360 Network Ports | Xbox Live Network Ports&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Jun 2014 22:58:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8485#M6266</guid>
      <dc:creator>swoods79</dc:creator>
      <dc:date>2014-06-29T22:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Xbox Live with dynamic public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8486#M6267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Swoods,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I hope this KB doc will help you: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-3695"&gt;Palo Alto Networks Firewalls &amp;amp;amp; Xbox360 - Strict NAT&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 05:56:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8486#M6267</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-06-30T05:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Xbox Live with dynamic public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8487#M6268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Swoods,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please give us an explanation about "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;NAT type as Strict which causes Xbox Live to not function properly" in details. Also, please let us know, what application you have set in the security policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 06:34:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8487#M6268</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-06-30T06:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Xbox Live with dynamic public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8488#M6269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The user supplied solution that Hulk shows only works if you can configure static nat.&amp;nbsp; Obviously that is not an option in your case where you have a dynamic ISP and only the one address available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would start by taking the xbox off the existing outbound policy and give it on without any url filtering or inspection at all.&amp;nbsp; Then see if that changes your Xbox live test status.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 11:59:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8488#M6269</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-06-30T11:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Xbox Live with dynamic public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8489#M6270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I've already tried this and it made no difference.&amp;nbsp; I need to define the NAT policy but the nature of having a dynamic IP for the external connection is confusing me.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did find this document: &lt;A _jive_internal="true" class="loading" href="https://live.paloaltonetworks.com/docs/DOC-3095" title="https://live.paloaltonetworks.com/docs/DOC-3095"&gt;https://live.paloaltonetworks.com/docs/DOC-3095&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this mean that the only option would be to use a dynamic DNS host and then refer to the FQDN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 13:49:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8489#M6270</guid>
      <dc:creator>swoods79</dc:creator>
      <dc:date>2014-06-30T13:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Xbox Live with dynamic public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8490#M6271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Xbox Live generally requires several ports to be forwarded directly to the system if you can't use UPnP. Since the Palo Alto Networks firewalls drop UPnP traffic, you're limited to opening the ports that the Xbox wants. Those ports should be (Source: &lt;A href="http://forums.xbox.com/xbox_forums/xbox_support/f/9/t/157383.aspx" title="http://forums.xbox.com/xbox_forums/xbox_support/f/9/t/157383.aspx"&gt;Xbox.com Forums&lt;/A&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;UDP 53&lt;/LI&gt;&lt;LI&gt;TCP 53&lt;/LI&gt;&lt;LI&gt;TCP 80&lt;/LI&gt;&lt;LI&gt;UDP 88&lt;/LI&gt;&lt;LI&gt;UDP 3074&lt;/LI&gt;&lt;LI&gt;TCP 3074&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try creating a NAT rule for those six ports to forward to the Xbox. You will need to set up a DynDNS unless you want to track your dynamic IP and update it whenever your ISP changes it. If you have a cable modem or DSL, often times the IP stays the same unless the modem is unplugged for a few days. The lease on a lot of the major US ISPs tends to be about 3 days, but your mileage may vary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 16:30:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8490#M6271</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2014-06-30T16:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Xbox Live with dynamic public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8491#M6272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This would be a destination NAT correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 17:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8491#M6272</guid>
      <dc:creator>swoods79</dc:creator>
      <dc:date>2014-06-30T17:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Xbox Live with dynamic public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8492#M6273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct. You need to do D-NAT for those ports on your public IP (or DynDNS name) to the Xbox.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 17:29:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/xbox-live-with-dynamic-public-ip/m-p/8492#M6273</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2014-06-30T17:29:49Z</dc:date>
    </item>
  </channel>
</rss>

