<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The source port was natted to multiple source ports while the packets leaving the FW in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/417991#M93621</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried to increasing the session timeout, unfortunately it did not work.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DongQu_0-1625794639766.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34855iC8871F6B42299F6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DongQu_0-1625794639766.png" alt="DongQu_0-1625794639766.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DongQu_1-1625794737361.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34856iAB1695677DC16810/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DongQu_1-1625794737361.png" alt="DongQu_1-1625794737361.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As I only have 1 public IP for natting, is it possible to create a separate nat policy for a particular traffic?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jul 2021 01:40:32 GMT</pubDate>
    <dc:creator>DongQu</dc:creator>
    <dc:date>2021-07-09T01:40:32Z</dc:date>
    <item>
      <title>The source port was natted to multiple source ports while the packets leaving the FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/417707#M93586</link>
      <description>&lt;P&gt;Hello everyone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The NAT type we are using is "Dynamic IP and Port", the Palo Alto Networks firewall translates the source IP address or range to a single IP address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;for this conversion, when the packets arriving the FW, we can see the source port is all the same&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DongQu_1-1625733192489.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34833i52AFF85A098E7A4F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DongQu_1-1625733192489.png" alt="DongQu_1-1625733192489.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But while the packets leaving the FW, the source port was natted to multiple ports&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DongQu_0-1625733419236.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34834iBED958151E9BF4CE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DongQu_0-1625733419236.png" alt="DongQu_0-1625733419236.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This brings a problem that the destination will close the conversion once it detects the source port changed.&lt;/P&gt;&lt;P&gt;Is there any way to keep the source port is natted to a single port all the time?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 08:37:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/417707#M93586</guid>
      <dc:creator>DongQu</dc:creator>
      <dc:date>2021-07-08T08:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: The source port was natted to multiple source ports while the packets leaving the FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/417905#M93606</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/111465"&gt;@DongQu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's doing what you're asking it to. You would want this traffic hitting a NAT rulebase entry using "Dynamic IP" as the translation type instead of "Dynamic IP and Port". Due to this traffic likely hitting a global rule utilized across the environment, I would recommend creating a&amp;nbsp;&lt;EM&gt;new&amp;nbsp;&lt;/EM&gt;rule and making it as specific as possible so that it's only matching the intended traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 18:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/417905#M93606</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-07-08T18:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: The source port was natted to multiple source ports while the packets leaving the FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/417972#M93616</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/111465"&gt;@DongQu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;wrote the firewall is doing what it is configured to. For every session it assigns a "random" source port for the NATed connection. The reason that the source port after NAT changes because the firewall sees these as new sessions. By default the UDP timeout is 30 seconds. So if there is no traffic more than 30 seconds the session is removed from the sessiontable and for the next packet a new session is created in the session table. In your situation it should work if you increase the session timeout for this UDP traffic because then as long as there is traffic the firewall will also keep the same source port after NAT is applied.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 21:57:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/417972#M93616</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-08T21:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: The source port was natted to multiple source ports while the packets leaving the FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/417991#M93621</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried to increasing the session timeout, unfortunately it did not work.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DongQu_0-1625794639766.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34855iC8871F6B42299F6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DongQu_0-1625794639766.png" alt="DongQu_0-1625794639766.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DongQu_1-1625794737361.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34856iAB1695677DC16810/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DongQu_1-1625794737361.png" alt="DongQu_1-1625794737361.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As I only have 1 public IP for natting, is it possible to create a separate nat policy for a particular traffic?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 01:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/417991#M93621</guid>
      <dc:creator>DongQu</dc:creator>
      <dc:date>2021-07-09T01:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: The source port was natted to multiple source ports while the packets leaving the FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/418015#M93624</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/111465"&gt;@DongQu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What application does your firewall see for this traffic in the logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the separate policy: With only one IP I would not recommend that. Mainly because you still need this IP for the general dynamic IP and port NAT rule. It might work, but I personally would not mix that.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 06:49:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/418015#M93624</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-09T06:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: The source port was natted to multiple source ports while the packets leaving the FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/418030#M93625</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"unknown udp", so I defined an application and specified the "udp timeout", it worked.&lt;/P&gt;&lt;P&gt;but I am not sure why the "session timeout" does not work in the global setting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 07:33:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-source-port-was-natted-to-multiple-source-ports-while-the/m-p/418030#M93625</guid>
      <dc:creator>DongQu</dc:creator>
      <dc:date>2021-07-09T07:33:46Z</dc:date>
    </item>
  </channel>
</rss>

