<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389659#M90639</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/156321"&gt;@stef&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As it is showing the incomplete and you are facing problems to reach only the&amp;nbsp; internet, you need to first verify the NAT configuration and check if Source NAT before going to ISP gateway is happening properly. Although the IPSEC is working fine through the circuit, re-verify the reverse path/routing config if it is clear. You need to have routes on the firewall to reach the backend hosts subnet who are sending the internet requests.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Mar 2021 06:30:48 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2021-03-08T06:30:48Z</dc:date>
    <item>
      <title>NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389568#M90631</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;we have configuration with dual ISP.&lt;/P&gt;&lt;P&gt;From the 1st provider we get public IP directly on the PA&lt;/P&gt;&lt;P&gt;2nd provider is with nat, i mean on PA we have private IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the route goes through the 1st one everything works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we switch to the 2nd one there is a problems . In the monitoring tab i can see all requests&amp;nbsp; to Internet zone&amp;nbsp; ends with "Incomplete, aged out".&lt;/P&gt;&lt;P&gt;Meanwhile we have IPSec's configured and they worked just fine from the both providers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone suggest what can be the problem?&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Mar 2021 08:27:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389568#M90631</guid>
      <dc:creator>stef</dc:creator>
      <dc:date>2021-03-07T08:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389659#M90639</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/156321"&gt;@stef&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As it is showing the incomplete and you are facing problems to reach only the&amp;nbsp; internet, you need to first verify the NAT configuration and check if Source NAT before going to ISP gateway is happening properly. Although the IPSEC is working fine through the circuit, re-verify the reverse path/routing config if it is clear. You need to have routes on the firewall to reach the backend hosts subnet who are sending the internet requests.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 06:30:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389659#M90639</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-03-08T06:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389872#M90656</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I agree this sounds like a routing/NAT issue. Are you using PBF for the fail over? Or are both ISP's live at the same time and routing traffic?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 22:14:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389872#M90656</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-03-08T22:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389993#M90674</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I dont use PBF. They are both up.&lt;/P&gt;&lt;P&gt;I have default routes with different Metrics&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 13:54:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389993#M90674</guid>
      <dc:creator>stef</dc:creator>
      <dc:date>2021-03-09T13:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389999#M90676</link>
      <description>&lt;P&gt;Just agreeing with everybody else really, it does sound like a NAT issue, I would make sure all routes and NAT's makes sense and then look further from there.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 14:01:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/389999#M90676</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-03-09T14:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/391136#M90754</link>
      <description>&lt;P&gt;Indeed it was routing issue.&lt;/P&gt;&lt;P&gt;I push the config from Panorama.&lt;/P&gt;&lt;P&gt;Nat policy changed to ISP2, but the default route remain the same because the Virtual router config was &lt;SPAN&gt;overwritten and the changes from panorama didnt applied . &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you all for your responses!&lt;/P&gt;</description>
      <pubDate>Sun, 14 Mar 2021 14:37:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-question/m-p/391136#M90754</guid>
      <dc:creator>stef</dc:creator>
      <dc:date>2021-03-14T14:37:08Z</dc:date>
    </item>
  </channel>
</rss>

