<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ICMP reply from the firewall instead of endpoint destination in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/icmp-reply-from-the-firewall-instead-of-endpoint-destination/m-p/231321#M66414</link>
    <description>&lt;P&gt;Hello everybody,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What could cause ping to respond from a different IP?&lt;BR /&gt;When tested from source, the response message of the ping command is successful and it's coming from the PaloAlto firewall, not from the destination IP.&lt;BR /&gt;Where and how can I verify on the PaloAlto if this is expected or not?&lt;BR /&gt;What setup can cause such behavior on the PaloAlto?&lt;BR /&gt;Need to mention that the destination is RPC server to which the source can't connect, even though there is sucessful ICMP reply from the PaloAlto firewall.&amp;nbsp;&lt;BR /&gt;Source and destinaiton are on different networks.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 18 Sep 2018 21:12:23 GMT</pubDate>
    <dc:creator>000000</dc:creator>
    <dc:date>2018-09-18T21:12:23Z</dc:date>
    <item>
      <title>ICMP reply from the firewall instead of endpoint destination</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp-reply-from-the-firewall-instead-of-endpoint-destination/m-p/231321#M66414</link>
      <description>&lt;P&gt;Hello everybody,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What could cause ping to respond from a different IP?&lt;BR /&gt;When tested from source, the response message of the ping command is successful and it's coming from the PaloAlto firewall, not from the destination IP.&lt;BR /&gt;Where and how can I verify on the PaloAlto if this is expected or not?&lt;BR /&gt;What setup can cause such behavior on the PaloAlto?&lt;BR /&gt;Need to mention that the destination is RPC server to which the source can't connect, even though there is sucessful ICMP reply from the PaloAlto firewall.&amp;nbsp;&lt;BR /&gt;Source and destinaiton are on different networks.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 21:12:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp-reply-from-the-firewall-instead-of-endpoint-destination/m-p/231321#M66414</guid>
      <dc:creator>000000</dc:creator>
      <dc:date>2018-09-18T21:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP reply from the firewall instead of endpoint destination</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp-reply-from-the-firewall-instead-of-endpoint-destination/m-p/231586#M66496</link>
      <description>&lt;P&gt;Incorrect implementation of NAT could cause the firewall to assume 'ownership' of IP addresses through proxy-arp&lt;/P&gt;
&lt;P&gt;This typically happens if the destination in a NAT policy is set to a subnet&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 08:30:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp-reply-from-the-firewall-instead-of-endpoint-destination/m-p/231586#M66496</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-09-20T08:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP reply from the firewall instead of endpoint destination</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp-reply-from-the-firewall-instead-of-endpoint-destination/m-p/231607#M66503</link>
      <description>&lt;P&gt;Indeed, it was found that there is a NAT which causes the reply from the firewall.&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;The traffic in question only returns through the firewall and hits NAT rule on it's way back.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;However that traffic does not go through the firewall on it's way out.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ICMP is not affected by it, but any TCP will be dropped because breaks the 3-way handshake.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 11:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp-reply-from-the-firewall-instead-of-endpoint-destination/m-p/231607#M66503</guid>
      <dc:creator>000000</dc:creator>
      <dc:date>2018-09-20T11:32:43Z</dc:date>
    </item>
  </channel>
</rss>

