<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT issue for accessing ICMC service from google in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/394327#M91105</link>
    <description>&lt;P&gt;&lt;SPAN&gt;The IPs are one to one static public IP addresses configured and that is not we want.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Mar 2021 13:18:03 GMT</pubDate>
    <dc:creator>gasin1</dc:creator>
    <dc:date>2021-03-26T13:18:03Z</dc:date>
    <item>
      <title>NAT issue for accessing ICMC service from google</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/393768#M91047</link>
      <description>&lt;P&gt;We have 4 production servers are accessing ICMC service which is hosted in following URL “pubsub.googleapis.com”,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If all 4 servers in common NAT rule then there is a time-out error observed which caused ICMC service failure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have tried change the rule from FQDN and category based rule but still time-out noticed ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application team escalated to Google support ,though they are not able to find the root cause ,However ,Suggested to change TCP time wait session to 120 sec but it didn’t restore the failure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a workaround ,We assigned dedicated IP’s for each servers which resolve the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way we could implement the NAT rule for these 4 servers, PAT is not working as well for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 10:09:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/393768#M91047</guid>
      <dc:creator>gasin1</dc:creator>
      <dc:date>2021-03-25T10:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue for accessing ICMC service from google</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/393871#M91055</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176348"&gt;@gasin1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;When you gave each server it's own IP address did you re-use the one that they were all trying to share at all? The thought process being that if you didn't, Google may simply be restricting the number of connections they are allowing from a single IP address for that service.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 14:19:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/393871#M91055</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-03-25T14:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue for accessing ICMC service from google</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/393895#M91061</link>
      <description>&lt;P&gt;The IPs are one to one static public IP addresses configured and that is not we want.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 14:59:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/393895#M91061</guid>
      <dc:creator>gasin1</dc:creator>
      <dc:date>2021-03-25T14:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue for accessing ICMC service from google</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/394327#M91105</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The IPs are one to one static public IP addresses configured and that is not we want.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 13:18:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/394327#M91105</guid>
      <dc:creator>gasin1</dc:creator>
      <dc:date>2021-03-26T13:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue for accessing ICMC service from google</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/394499#M91150</link>
      <description>&lt;P&gt;Did you try to increase the tcp timeout on the firewall as this could be the reason for the issue by creatinga custom service (also global session timeout or application override can be used by the service timeout is a better option)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRiCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRiCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRiCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRiCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to know which timeout you are hiting use global counters with a filter:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my point of view destination NAT with FQDN is still the best option for you:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/configure-nat/configure-destination-nat-using-dynamic-ip-addresses.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/configure-nat/configure-destination-nat-using-dynamic-ip-addresses.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 20:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-issue-for-accessing-icmc-service-from-google/m-p/394499#M91150</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-26T20:55:08Z</dc:date>
    </item>
  </channel>
</rss>

