<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inbound NAT with Port Redirection for port 443 using a single outside interface IP ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-nat-with-port-redirection-for-port-443-using-a-single/m-p/241862#M69247</link>
    <description>&lt;P&gt;Can you share screenshot of your NAT and Security policy?&lt;/P&gt;</description>
    <pubDate>Mon, 03 Dec 2018 15:50:39 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2018-12-03T15:50:39Z</dc:date>
    <item>
      <title>Inbound NAT with Port Redirection for port 443 using a single outside interface IP ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-nat-with-port-redirection-for-port-443-using-a-single/m-p/241778#M69233</link>
      <description>&lt;P&gt;My ISP only provides a single ip address for the outside interface via DHCP.&lt;/P&gt;&lt;P&gt;I would like to forward port 443 to and internal host, but Palo keeps dropping the packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems as if the device management restriction is responsible for this, but I have removed that policy from the external interface so I am not sure why this is getting filtered. See console message below.&lt;BR /&gt;&lt;BR /&gt;Inbound rules are set to ANY and SSH port forwarding inbound works without any problem.&lt;/P&gt;&lt;P&gt;Packet drops were inspected with packet filtering so I know the packets are dropped by Palo. Packets (rx,fw,dr) increasing while no tx.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA1(active)&amp;gt; show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 45.132 seconds&lt;/P&gt;&lt;P&gt;name value rate severity category aspect description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;pkt_sent_host 6 0 info packet pktproc Packets successfully transmitted to host interface&lt;BR /&gt;session_allocated 6 0 info session resource Sessions allocated&lt;BR /&gt;session_installed 6 0 info session resource Sessions installed&lt;BR /&gt;session_discard 6 0 info session resource Session set to discard by security policy check&lt;BR /&gt;flow_host_pkt_xmt 27 0 info flow mgmt Packets transmitted to control plane&lt;BR /&gt;flow_host_service_deny 6 0 drop flow mgmt Device management session denied&lt;BR /&gt;flow_host_vardata_rate_limit_ok 27 0 info flow mgmt Host vardata not sent: rate limit ok&lt;BR /&gt;flow_ip_cksm_sw_validation 6 0 info flow pktproc Packets for which IP checksum validation was done in software&lt;BR /&gt;ha_msg_sent 15 0 info ha system HA: messages sent&lt;BR /&gt;ha_session_setup_msg_sent 6 0 info ha pktproc HA: session setup messages sent&lt;BR /&gt;ha_session_update_msg_sent 9 0 info ha pktproc HA: session update messages sent&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Total counters shown: 11&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;admin@PA1(active)&amp;gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Dec 2018 23:48:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-nat-with-port-redirection-for-port-443-using-a-single/m-p/241778#M69233</guid>
      <dc:creator>aarato</dc:creator>
      <dc:date>2018-12-02T23:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound NAT with Port Redirection for port 443 using a single outside interface IP ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-nat-with-port-redirection-for-port-443-using-a-single/m-p/241862#M69247</link>
      <description>&lt;P&gt;Can you share screenshot of your NAT and Security policy?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 15:50:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-nat-with-port-redirection-for-port-443-using-a-single/m-p/241862#M69247</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-12-03T15:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound NAT with Port Redirection for port 443 using a single outside interface IP ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-nat-with-port-redirection-for-port-443-using-a-single/m-p/243262#M69572</link>
      <description>&lt;P&gt;Thanks for the reply unfortunately, I couldn't share the live environment, so I labbed it out and it works well in the lab environment. Thanks for the reply though.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 03:13:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-nat-with-port-redirection-for-port-443-using-a-single/m-p/243262#M69572</guid>
      <dc:creator>aarato</dc:creator>
      <dc:date>2018-12-14T03:13:40Z</dc:date>
    </item>
  </channel>
</rss>

