<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Only works part of the time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/262211#M74307</link>
    <description>&lt;P&gt;Just an FYI, the issue was finally determined to be a bug in Pan-OS 8.0 - 8.1.6.&amp;nbsp; (PAN-103023).&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 24 May 2019 16:46:04 GMT</pubDate>
    <dc:creator>Brad.Herbert</dc:creator>
    <dc:date>2019-05-24T16:46:04Z</dc:date>
    <item>
      <title>NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231300#M66408</link>
      <description>&lt;P&gt;Ok, Who knows what's going here...Here is my Scenario..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're looking at a new Phone Platform and I'm only able to get a NAT to work part of the time.&amp;nbsp; First, when the IP Phone loads, internal address of 172.23.1.1, It connects out to the Platform IP of 55.66.77.88, downloads the config from it's TFTP Service.&amp;nbsp; Since we don't want our Voice traffic mingled in with our other public traffic, we've NAT'd 172.23.0.0 /16 to a Public IP of 192.15.15.15, the NAT Works perfectly here.&amp;nbsp; Next, once the TFTP Load is complete, the Phone tries to register via SIP, same Internal Address 172.23.1.1 to the platform of 55.66.77.88, however the same NAT Statement is not being used.&amp;nbsp; I've ran numerous PCAP's, changed NAT several times, moved rules, but everything appears correct.&amp;nbsp; Furthermore, when I run test nat-policy-match with the proper destination and source on port 5060 and protocol 17, it test out correctly.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup is...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inside Zone to Destination Zone, source address 172.23.0.0/16 to destination address 55.66.77.88, any interface and any service translate type Dynamic IP address of 192.15.15.15.&amp;nbsp; Anyone have any idea what's going on and why the NAT isn't getting applied 100% of the time?&amp;nbsp; When I look at the Web GUI of the phone platform, it's showing my phone as being registered with our Public IP of 192.15.15.8.&amp;nbsp; I am able to place and receive a call, however there is not audio.&amp;nbsp; Running another PCAP for a call session, all UDP packets from 172.23.1.1 are getting dropped.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing to note, SIP ALG is turned enabled, though I'm not sure if that's the issue.&amp;nbsp; Do try to get around SIP ALG, I created a custom Application, mirrored from SIP, and setup an Application Override with Inside/Outside, all IP's and UDP 5060, but still having the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've opened a Support Case, but with it being a low priority, thought I'd reach out to the community to see if anyone has ran into this issue inthe past.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're running 8.0.8 PAN-OS version.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 20:07:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231300#M66408</guid>
      <dc:creator>Brad.Herbert</dc:creator>
      <dc:date>2018-09-18T20:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231587#M66497</link>
      <description>&lt;P&gt;try dynamic-ip-and-port&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;with dynamic IP you may be running out of ip-port combinations and breaking NAT because you only have 1 single IP and are forcing port reuse (oversubscription of more than 8x will be reached quickly)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if your SIP implementation doesn;t allow the varying source ports, you'll need a bigger subnet to NAT your phones&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 08:34:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231587#M66497</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-09-20T08:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231616#M66504</link>
      <description>&lt;P&gt;I've changed to dynamin-ip-and-port, however I'm still getting the same results.&amp;nbsp; Currently, we're just testing with one phone back to the new PBX solution.&amp;nbsp; Support hasn't been any help, they've asked that I clear all sessions, would be suprised if that actually works.&amp;nbsp; Doesn't matter what I try, the TFTP Download from the PBX utilizes the NAT however the SIP Registration does not, same source and Destination addresses for both the TFTP Download and SIP Registration.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 12:49:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231616#M66504</guid>
      <dc:creator>Brad.Herbert</dc:creator>
      <dc:date>2018-09-20T12:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231624#M66508</link>
      <description>&lt;P&gt;Have you set a filter and checked the global counters? SIP has this thing where it sometimes reuses all the session parameters (source ports et al) of the previous session, which the firewall doesn't like&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that will likely show up in error counters&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;additionally, you could try disabling the ALG on the sip application,&amp;nbsp;or try an app override altogether&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 14:31:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231624#M66508</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-09-20T14:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231801#M66551</link>
      <description>&lt;P&gt;Finally have the NAT working 100% of the time, had to clear the old SIP Sessions.&amp;nbsp; However, Audio still is an issue so I'm going to try building out an Applicaion Override to see if that works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 19:10:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231801#M66551</guid>
      <dc:creator>Brad.Herbert</dc:creator>
      <dc:date>2018-09-21T19:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231812#M66555</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Could you expand on the issues you are having with audio? i.e. poor quality, one side cannot hear, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 19:28:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231812#M66555</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-21T19:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231817#M66556</link>
      <description>&lt;P&gt;We aren't getting any audio, either way.&amp;nbsp; My Phone Rings just as it should, when I answer there isn't any audio either way.&amp;nbsp; Running PCAP's, I keep seeing 401 unauthorized responses back from the PBX.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even wierder, just called that test phone from my cell phone, I just left the call established and after about 4 Minutes, i had audio both ways?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 19:41:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231817#M66556</guid>
      <dc:creator>Brad.Herbert</dc:creator>
      <dc:date>2018-09-21T19:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231818#M66557</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So is it consistently working now or still takes minutes to connect?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 19:52:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231818#M66557</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-21T19:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231819#M66558</link>
      <description>&lt;P&gt;Once the call is connected, Audio is not getting passed until 2 minutes into the session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 19:58:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231819#M66558</guid>
      <dc:creator>Brad.Herbert</dc:creator>
      <dc:date>2018-09-21T19:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231820#M66559</link>
      <description>&lt;P&gt;Running another PCAP, i just noticed the Firewall is dropping UDP packets, inside to outside.&amp;nbsp; Looking back through, the source and destination ports are the same during the call, but are different with each call.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 20:00:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231820#M66559</guid>
      <dc:creator>Brad.Herbert</dc:creator>
      <dc:date>2018-09-21T20:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231822#M66560</link>
      <description>&lt;P&gt;Also check the logs, they should show what/where its getting blocked and you can adjust you policies accordingly.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 20:01:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231822#M66560</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-21T20:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231824#M66561</link>
      <description>&lt;P&gt;Going through the logs, nothing is being blocked by policy to/from by private address/NAT'd Address and the PBX.&amp;nbsp; Actually, the policy is set to allow any application, Service is Application-Default.&amp;nbsp; I enabled logging on my Interzone rule, however nothing is being dropped by policy, that I can find.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 20:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231824#M66561</guid>
      <dc:creator>Brad.Herbert</dc:creator>
      <dc:date>2018-09-21T20:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231841#M66565</link>
      <description>&lt;P&gt;I hear ya it can be a pain. We use Skype and I can tell you that even having the application set to any and service to application default was not enough. Skype/Lync use like almost every port 50K and up :(. Does your SIP terminate internally or does it flow out over the internet to the provider? I would also say call the provider and see if they can run a trace while your making the test call just to see if they see anything on their end.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 20:20:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/231841#M66565</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-21T20:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Only works part of the time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/262211#M74307</link>
      <description>&lt;P&gt;Just an FYI, the issue was finally determined to be a bug in Pan-OS 8.0 - 8.1.6.&amp;nbsp; (PAN-103023).&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2019 16:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-only-works-part-of-the-time/m-p/262211#M74307</guid>
      <dc:creator>Brad.Herbert</dc:creator>
      <dc:date>2019-05-24T16:46:04Z</dc:date>
    </item>
  </channel>
</rss>

