<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is the destination NAT configuration for Ping &amp;amp; trace-rout in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335251#M84501</link>
    <description>&lt;P&gt;Need to allow ping &amp;amp; trace route from Internet(outside) to Trust (Inside).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What need to be configured in Destination NAT to allow ping &amp;amp; traceroute ?&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jun 2020 11:19:42 GMT</pubDate>
    <dc:creator>Mohammed_Yasin</dc:creator>
    <dc:date>2020-06-25T11:19:42Z</dc:date>
    <item>
      <title>What is the destination NAT configuration for Ping &amp; trace-rout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335251#M84501</link>
      <description>&lt;P&gt;Need to allow ping &amp;amp; trace route from Internet(outside) to Trust (Inside).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What need to be configured in Destination NAT to allow ping &amp;amp; traceroute ?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 11:19:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335251#M84501</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-25T11:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: What is the destination NAT configuration for Ping &amp; trace-rout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335308#M84514</link>
      <description>&lt;P&gt;Continue of same...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;security policy section we allow the ping &amp;amp; trace route application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the service should be allowed in &amp;nbsp;NAT policy for ping &amp;amp; trace-route ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not want to configure ‘any any’ service in NAT policy to allow ping &amp;amp; trace-route ?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 14:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335308#M84514</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-25T14:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: What is the destination NAT configuration for Ping &amp; trace-rout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335400#M84523</link>
      <description>&lt;P&gt;If you are using the app-id/layer 7 in the policy then recommend using "Application default" for the service. You should not have to specify ports unless they are non-standard for the application in question.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 18:23:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335400#M84523</guid>
      <dc:creator>shawnhafen</dc:creator>
      <dc:date>2020-06-25T18:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: What is the destination NAT configuration for Ping &amp; trace-rout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335426#M84531</link>
      <description>&lt;P&gt;Thanks for the update..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Already I am using the application default...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But its I can use service in NAT policy instead of ANY and I want to use multiple services in nat policy rule.. it's possible to have in Orignal packet translation section&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its recommended ?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 20:35:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335426#M84531</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-25T20:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: What is the destination NAT configuration for Ping &amp; trace-rout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335427#M84532</link>
      <description>&lt;P&gt;Thanks for the update. Already I am using the application default... But its I can use service in NAT policy instead of ANY and I want to use multiple services in the nat policy rule. it's possible to have in the Orignal packet translation section Its recommended?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 20:36:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335427#M84532</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-25T20:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: What is the destination NAT configuration for Ping &amp; trace-rout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335445#M84535</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't believe this is possible without an 'any' service entry. ICMP traffic doesn't function on a L4 basis. The firewall takes the ID and sequence fields from the ICMP header and treats them the same as if they were ports, which is why setting the service to any works fine. PAN doesn't really have true support for making an ICMP NAT entry.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 21:32:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335445#M84535</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-25T21:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: What is the destination NAT configuration for Ping &amp; trace-rout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335676#M84600</link>
      <description>&lt;P&gt;Thanks for the update,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and for traceRoute in Nat Policy ?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jun 2020 06:10:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335676#M84600</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-28T06:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: What is the destination NAT configuration for Ping &amp; trace-rout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335730#M84614</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Depends on the system, as it's implemented differently between operating systems. Windows exclusively utilizes ICMP, so you would fall into the same scenario. Unix systems will actually utilize 33434-33534/UDP by default, but have options for using ICMP or even TCP depending on how the command is run.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Generally speaking traceroute will follow the same as ICMP; it won't work reliably unless you open all available ports via your NAT rulebase, and that's really very ill-advised when you're talking about allowing traffic inbound.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should have probably started with this, but what are you actually trying to achieve with this setup? So take away ICMP or traceroute, because at the moment we don't care about them. What were you trying to do with this setup? Some sort of status check on internal clients from an external resource?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jun 2020 16:37:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-destination-nat-configuration-for-ping-amp-trace/m-p/335730#M84614</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-28T16:37:50Z</dc:date>
    </item>
  </channel>
</rss>

