<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA sending TCP RST for a NAT rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323876#M82730</link>
    <description>&lt;P&gt;Agreed with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;Most of the time session shows incomplete when there is no reply back from server side. Routing issues mostly causes this.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Apr 2020 17:51:06 GMT</pubDate>
    <dc:creator>Vikashh</dc:creator>
    <dc:date>2020-04-20T17:51:06Z</dc:date>
    <item>
      <title>PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323806#M82715</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Adding a bidirectionnal NAT rule for an ssl web server and the according security rule, connections from outside are dropped as "Incomplete". Traffic capture show that first SYN packet received is directly rejected by PA with a RST response. What does it mean ?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 10:26:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323806#M82715</guid>
      <dc:creator>rodjeur68</dc:creator>
      <dc:date>2020-04-20T10:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323815#M82716</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138783"&gt;@rodjeur68&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As session is incomplete, there is no response/reply from destination end.&lt;/P&gt;&lt;P&gt;Please check few configurations like,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Routing for destination server&lt;/P&gt;&lt;P&gt;2. If service is up and running on the server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 11:33:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323815#M82716</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-04-20T11:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323817#M82717</link>
      <description>&lt;P&gt;Thx for the response.&lt;/P&gt;&lt;P&gt;* There's no routing issue: server can access Internet via the PA using the NAT IP address&lt;/P&gt;&lt;P&gt;* service is up and running, accessible from internal networks&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 11:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323817#M82717</guid>
      <dc:creator>rodjeur68</dc:creator>
      <dc:date>2020-04-20T11:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323819#M82718</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138783"&gt;@rodjeur68&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you seeing issues with inbound or outbound traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 12:27:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323819#M82718</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-04-20T12:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323822#M82720</link>
      <description>&lt;P&gt;Globally ? Not at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rodjeur68&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 12:35:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323822#M82720</guid>
      <dc:creator>rodjeur68</dc:creator>
      <dc:date>2020-04-20T12:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323848#M82722</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138783"&gt;@rodjeur68&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to share traffic logs for affected traffic? Also is it app-id based security policy ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you said in your post, you have bi-directional NAT and you are facing issues with connections from outside on one ssl web server. You are trying to externalize web-server probably on 443 port. As session is seems to be incomplete, just check if web-service is running on server that you want to externalize. Check if you are able to telnet internal server on web-service port from LAN. As you are seeing incomplete session, most of the time it happens when there is no response from the server. That's why i asked to check reverse routing for web server subnet on firewall and application running status on web server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 15:47:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323848#M82722</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-04-20T15:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323876#M82730</link>
      <description>&lt;P&gt;Agreed with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;Most of the time session shows incomplete when there is no reply back from server side. Routing issues mostly causes this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 17:51:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/323876#M82730</guid>
      <dc:creator>Vikashh</dc:creator>
      <dc:date>2020-04-20T17:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/324004#M82753</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for your time. As I mentionned in a previous post, I think we don't have any issue with routing and service is up and running:&lt;/P&gt;&lt;P&gt;* I can ping server from appliance&lt;/P&gt;&lt;P&gt;* show routing route gives a correct route for my internal subnet&lt;/P&gt;&lt;P&gt;* from server, I'm able to browse Internet using the external NAT IP choosen for service&lt;/P&gt;&lt;P&gt;* from internals subnets, I can access the https service on the server (nginx)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When I capture the traffic I can see RST tcp packet immediatly send by PA on external interface and nothing on the internal interface.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-04-21_10h19_39.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25281i4B3ED087C0D1373B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020-04-21_10h19_39.png" alt="2020-04-21_10h19_39.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 08:23:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/324004#M82753</guid>
      <dc:creator>rodjeur68</dc:creator>
      <dc:date>2020-04-21T08:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/324181#M82775</link>
      <description>&lt;P&gt;It is always safer to create 2 NAT policies for DNAT and SNAT than bi-direcitonal.&lt;/P&gt;&lt;P&gt;If you check bi-directional NAT rule in cli you can see that for DNAT source zone will be "any".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For your TCP RST problem. Most likely your security policy is incorrect.&lt;/P&gt;&lt;P&gt;Are you using pre-nat IP and post-nat zone in security policy?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 03:16:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/324181#M82775</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2020-04-22T03:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/324241#M82787</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you very much for your advice on NAT rules.&lt;/P&gt;&lt;P&gt;After another check of our configuration, it seems that another host in the same NML subnet not crossing the Palo appliance was using the same IP address ... Everything works as expected now, sorry for the time spent on this obvious problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rodjeur68&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 10:37:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/324241#M82787</guid>
      <dc:creator>rodjeur68</dc:creator>
      <dc:date>2020-04-22T10:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: PA sending TCP RST for a NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/374074#M89016</link>
      <description>&lt;P&gt;Hi, can you elaborate a little more about the "&lt;SPAN&gt;It is always safer to create 2 NAT policies for DNAT and SNAT than bi-direcitonal"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I do have most of mine NAT rule is currently provisioned bi-directional and we are seeing issue with client server session reset. So, I searched and see this thread but do not understand about the statement you metioned. Thanks much for your help and if you could help and give a sample practical NAT rule using two separates policies instead of one as you said.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 21:06:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-sending-tcp-rst-for-a-nat-rule/m-p/374074#M89016</guid>
      <dc:creator>BrianNg2020</dc:creator>
      <dc:date>2020-12-13T21:06:46Z</dc:date>
    </item>
  </channel>
</rss>

