<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT IP Pool Clean Up in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10285#M7562</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using the original IP address for the &amp;lt;source&amp;gt; and the translated address &amp;lt;xlate-source&amp;gt; since those would be the IP addresses the firewall would see on the original packet that hits the system. So for example, from the "show running nat-rule-ippool" I see,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;172.26.202.152&amp;nbsp;&amp;nbsp; xxx.xxx.xxx.104 &lt;/TD&gt;&lt;TD&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I can find,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crclark@scea-rhq-sc-pa5050a(active)&amp;gt; show session all filter source 172.26.202.152&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application&amp;nbsp;&amp;nbsp;&amp;nbsp; State&amp;nbsp;&amp;nbsp; Type Flag&amp;nbsp; Src[Sport]/Zone/Proto (translated IP[Port])&lt;/P&gt;&lt;P&gt;Vsys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dst[Dport]/Zone (translated IP[Port])&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;889910&amp;nbsp; playstation-network ACTIVE&amp;nbsp; FLOW&amp;nbsp; NS&amp;nbsp;&amp;nbsp; 172.26.202.152[51781]/bp-gaming/6&amp;nbsp; (xxx.xxx.xxx.104[51781])&lt;/P&gt;&lt;P&gt;vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 54.241.139.10[443]/internet&amp;nbsp; (54.241.139.10[443])&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if I look for,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;172.26.200.133&amp;nbsp;&amp;nbsp; xxx.xxx.xxx.161 &lt;/TD&gt;&lt;TD&gt;30&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crclark@scea-rhq-sc-pa5050a(active)&amp;gt; show session all filter source 172.26.200.133&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No Active Sessions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if there were to have been an incoming connection (there really shouldn't be, but since I'm troubleshooting, I want to cover all possibilities), it would be found with,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crclark@scea-rhq-sc-pa5050a(active)&amp;gt; show session all filter destination xxx.xxx.xxx.161&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No Active Sessions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since that would have been the IP address on the original packet that came in from the Internet side before NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I understand why 172.26.202.152 is still holding a slot in the IP pool, but why is 172.26.200.133?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Aug 2013 23:46:51 GMT</pubDate>
    <dc:creator>cosx</dc:creator>
    <dc:date>2013-08-19T23:46:51Z</dc:date>
    <item>
      <title>NAT IP Pool Clean Up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10281#M7558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having a problem with a NAT IP pool filling up. There are 92 IP addresses in the pool which should be plenty compared to the number of active clients. However, the pool is filling up. When I go to look at what active sessions a given IP address has, I find that many have no active sessions (with "show session all filter source &amp;lt;ip&amp;gt;" or "show session all filter destination &amp;lt;xlate-source&amp;gt;"). So why are they still consuming an address in the pool? I notice in the "show running nat-rule-ippool" output, that there is nothing in the "TTL" field. Is that expected? Is there a way to manually flush an entry or the whole list? The "clear nat-rule-cache" command does not seem to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running 4.1.2 on a PA-5050.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 20:16:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10281#M7558</guid>
      <dc:creator>cosx</dc:creator>
      <dc:date>2013-08-19T20:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAT IP Pool Clean Up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10282#M7559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are we using "dynamic IP" or "dynamic IP and Port" ? From the description, it looks like we are using a pool, ie "Dynamic IP". The command "show running nat-rule-ippool" works only for "Dynamic IP and Port"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try out the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;debug dataplane nat sync-ippool rule&amp;lt;rulename&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;Here are some helpful links:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3452"&gt;https://live.paloaltonetworks.com/docs/DOC-3452&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4891"&gt;https://live.paloaltonetworks.com/docs/DOC-4891&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;BR,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;Karthik &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 20:40:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10282#M7559</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-19T20:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: NAT IP Pool Clean Up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10283#M7560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition, &lt;/P&gt;&lt;P&gt;when you are trying to match for sessions that are source translated, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) The &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;"show session all filter source &amp;lt;ip&amp;gt;", where&amp;nbsp; &amp;lt;ip&amp;gt;&amp;nbsp; is one of&amp;nbsp; the "Source Nated IP from the pool", will not show us any results. This is because the session is initiated from the original source, whose IP later gets translated to one of the IPs from the pool. This command is valid for pre-translated source IP addresses and not the post translated IP addresses.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) On similar lines, the command &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; "show session all filter destination &amp;lt;xlate-source&amp;gt;", wouldnt work for post translated source IP addresses, because from the PANFWs standpoint the destination is the real IP address and not the translated IP address. ( this command would however work for pre translated destination NAT IP address )&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence for both the cases, you will never see any sessions, and this is an expected behavior.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 21:12:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10283#M7560</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-19T21:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAT IP Pool Clean Up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10284#M7561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am indeed doing one-to-one NAT, "dynamic IP" only. I do get output from "show running nat-rule-ippool." Are you saying the output is bogus?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crclark@scea-rhq-sc-pa5050a(active)&amp;gt; show running nat-rule-ippool rule "Gaming to Internet"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rule: Gaming to Internet&lt;/P&gt;&lt;P&gt;-----------------------------------------&lt;/P&gt;&lt;P&gt;Reserve IP: no&lt;/P&gt;&lt;P&gt;0.0.0.0-255.255.255.255 =&amp;gt; xxx.xxx.xxx.100-xxx.xxx.xxx.191&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Xlat-Source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ref. Cnt&amp;nbsp;&amp;nbsp; TTL(s)&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;---------------- ---------------- ---------- ----------&lt;/P&gt;&lt;P&gt;172.26.200.133&amp;nbsp;&amp;nbsp; xxx.xxx.xxx.161&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;172.26.200.250&amp;nbsp;&amp;nbsp; xxx.xxx.xxx.101&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 980&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;172.26.75.32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; xxx.xxx.xxx.108&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;172.26.201.27&amp;nbsp;&amp;nbsp;&amp;nbsp; xxx.xxx.xxx.166&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;172.26.202.152&amp;nbsp;&amp;nbsp; xxx.xxx.xxx.104&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;[snip]&lt;/P&gt;&lt;P&gt;Total IPs in use: 88&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Total entries in time-reserve cache: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Total freelist left: 92&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 23:37:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10284#M7561</guid>
      <dc:creator>cosx</dc:creator>
      <dc:date>2013-08-19T23:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: NAT IP Pool Clean Up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10285#M7562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using the original IP address for the &amp;lt;source&amp;gt; and the translated address &amp;lt;xlate-source&amp;gt; since those would be the IP addresses the firewall would see on the original packet that hits the system. So for example, from the "show running nat-rule-ippool" I see,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;172.26.202.152&amp;nbsp;&amp;nbsp; xxx.xxx.xxx.104 &lt;/TD&gt;&lt;TD&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I can find,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crclark@scea-rhq-sc-pa5050a(active)&amp;gt; show session all filter source 172.26.202.152&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application&amp;nbsp;&amp;nbsp;&amp;nbsp; State&amp;nbsp;&amp;nbsp; Type Flag&amp;nbsp; Src[Sport]/Zone/Proto (translated IP[Port])&lt;/P&gt;&lt;P&gt;Vsys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dst[Dport]/Zone (translated IP[Port])&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;889910&amp;nbsp; playstation-network ACTIVE&amp;nbsp; FLOW&amp;nbsp; NS&amp;nbsp;&amp;nbsp; 172.26.202.152[51781]/bp-gaming/6&amp;nbsp; (xxx.xxx.xxx.104[51781])&lt;/P&gt;&lt;P&gt;vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 54.241.139.10[443]/internet&amp;nbsp; (54.241.139.10[443])&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if I look for,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;172.26.200.133&amp;nbsp;&amp;nbsp; xxx.xxx.xxx.161 &lt;/TD&gt;&lt;TD&gt;30&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crclark@scea-rhq-sc-pa5050a(active)&amp;gt; show session all filter source 172.26.200.133&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No Active Sessions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if there were to have been an incoming connection (there really shouldn't be, but since I'm troubleshooting, I want to cover all possibilities), it would be found with,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crclark@scea-rhq-sc-pa5050a(active)&amp;gt; show session all filter destination xxx.xxx.xxx.161&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No Active Sessions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since that would have been the IP address on the original packet that came in from the Internet side before NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I understand why 172.26.202.152 is still holding a slot in the IP pool, but why is 172.26.200.133?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 23:46:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10285#M7562</guid>
      <dc:creator>cosx</dc:creator>
      <dc:date>2013-08-19T23:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAT IP Pool Clean Up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10286#M7563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you confirm that you are currently running PAN-OS 4.1.2 ? If so then there were some NAT pool leak issues resolved between that release and latest 4.1.x release which is 4.1.14. If indeed on 4.1.2 then I would recommend scheduling an upgrade to 4.1.14 and see if you still have issues. If you continue to have NAT pool issues with 4.1.14, then I would recommend to open a support case to have TAC investigate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Richard &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Aug 2013 05:12:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10286#M7563</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-21T05:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT IP Pool Clean Up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10287#M7564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry about that, the version is actually 4.1.6. (When I first looked at the "show system info" output, the "logdb-version: 4.1.2" line caught my eye first.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, now I'm not really sure I even have a problem... Upon some more testing, it look like even though I have 92 translations "in use," when I actually try to create a new translation, it works. One of the translations that's listed gets bumped out. Presumably it's one of those that has no active sessions associated with it. Maybe the PAN retains some memory of inactive sessions so internal IPs get the same external IP address next time, but those external IPs are still available to new active sessions if needed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So now I may have to look elsewhere for what caused our problems... or maybe we really did run out of mapped addresses. Seems I can't tell by just looking at "show running nat-rule-ippool" how many addresses are &lt;EM&gt;really&lt;/EM&gt; available, if the IP pool is at 100% usage.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Aug 2013 17:59:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-ip-pool-clean-up/m-p/10287#M7564</guid>
      <dc:creator>cosx</dc:creator>
      <dc:date>2013-08-26T17:59:12Z</dc:date>
    </item>
  </channel>
</rss>

