<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User's in session table hitting wrong NAT rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/426665#M94519</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a client that has several NAT rule's (as per below). The have discovered in the session table 2 IP's from the 10.128.48.0/22 subnet seem to be hitting &lt;EM&gt;'guest_nat'&lt;/EM&gt; rule below when they should be hitting the &lt;EM&gt;'users_nat' &lt;/EM&gt;rule below. When testing the NAT policy match with the affected IPs they hit the correct NAT rule (users_nat).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are currently migrating some of security policy rules to use group mappings, but I don't believe that would affect this in anyway, but could be wrong.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Affected IPs:&lt;/P&gt;&lt;P&gt;10.128.48.10/22&lt;/P&gt;&lt;P&gt;10.128.48.11/22&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@fw1(active)&amp;gt; test nat-policy-match protocol 6 from users to untrust source 10.128.48.11 destination 216.239.38.210 destination-port 443&lt;/P&gt;&lt;P&gt;Source-NAT: Rule matched: users_nat&lt;BR /&gt;10.128.48.11:0 =&amp;gt; 203.100.5.6:51317 (6),&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@fw1(active)&amp;gt; show running nat-policy &amp;lt;------ removed non relevant NAT policies&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;"users_nat; index: 16" {&lt;BR /&gt;nat-type ipv4;&lt;BR /&gt;from users;&lt;BR /&gt;source 10.128.48.0/22;&lt;BR /&gt;to untrust;&lt;BR /&gt;to-interface ;&lt;BR /&gt;destination any;&lt;BR /&gt;service 0:any/any/any;&lt;BR /&gt;translate-to "src: 203.100.5.6 (dynamic-ip-and-port) (pool idx: 1)";&lt;BR /&gt;terminal no;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;"guest_nat; index: 18" {&lt;BR /&gt;nat-type ipv4;&lt;BR /&gt;from guest;&lt;BR /&gt;source 10.128.16.0/20;&lt;BR /&gt;to untrust;&lt;BR /&gt;to-interface ;&lt;BR /&gt;destination any;&lt;BR /&gt;service 0:any/any/any;&lt;BR /&gt;translate-to "src: 203.100.5.6 (dynamic-ip-and-port) (pool idx: 1)";&lt;BR /&gt;terminal no;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@fw1(active)&amp;gt; show running nat-rule-ippool rule users_nat&lt;/P&gt;&lt;P&gt;VSYS 1 Rule users_nat:&lt;BR /&gt;Rule: users_nat, Pool index: 1, memory usage: 36472&lt;BR /&gt;-----------------------------------------&lt;BR /&gt;Oversubscription Ratio: 4&lt;BR /&gt;Number of Allocates: 367534&lt;BR /&gt;Last Allocated Index: 39302&lt;BR /&gt;-----------------------------------------&lt;BR /&gt;------------ Private Pool ---------------&lt;BR /&gt;Number of Allocates: 0&lt;BR /&gt;Last Allocated Index: 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@fw1(active)&amp;gt; show running nat-rule-ippool rule guest_nat&lt;/P&gt;&lt;P&gt;VSYS 1 Rule guest_nat:&lt;BR /&gt;Rule: guest_nat, Pool index: 1, memory usage: 36472&lt;BR /&gt;-----------------------------------------&lt;BR /&gt;Oversubscription Ratio: 4&lt;BR /&gt;Number of Allocates: 367552&lt;BR /&gt;Last Allocated Index: 54244&lt;BR /&gt;-----------------------------------------&lt;BR /&gt;------------ Private Pool ---------------&lt;BR /&gt;Number of Allocates: 0&lt;BR /&gt;Last Allocated Index: 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@fw1(active)&amp;gt; show running global-ippool&lt;/P&gt;&lt;P&gt;Idx Type From To ToNum Ref. Cnt Mem Size Ratio Ready&lt;BR /&gt;---- --------------- -------------------------------- --------------- ----- -------- -------- ----- ------&lt;BR /&gt;1 Dynamic IP/Port 10.128.48.0-10.128.51.255 203.100.5.6 1 4 36472 4 k1 /p1&lt;BR /&gt;2 Dynamic IP/Port 10.128.12.0-10.128.13.255 203.100.5.10 1 2 36472 4 k1 /p1&lt;BR /&gt;3 Dynamic IP/Port 10.0.98.0-10.0.98.255 203.100.5.7 1 2 36472 4 k1 /p1&lt;BR /&gt;4 Dynamic IP/Port 10.40.0.7-10.40.0.7 203.100.4.140 1 1 36472 4 k1 /p1&lt;BR /&gt;5 Dynamic IP/Port 10.0.35.0-10.0.35.255 203.100.4.142 1 1 36472 4 k1 /p1&lt;/P&gt;&lt;P&gt;Usable NAT DIP/DIPP shared memory size: 61785060&lt;BR /&gt;Used NAT DIP/DIPP shared memory size: 182360(0.30%)&lt;BR /&gt;Dynamic IP NAT Pool: 0(0.00%)&lt;BR /&gt;Dynamic IP/Port NAT Pool: 5(0.30%)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@fw1(active)&amp;gt; show session info&lt;/P&gt;&lt;P&gt;target-dp: *.dp0&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Number of sessions supported: 2097150&lt;BR /&gt;Number of allocated sessions: 692&lt;BR /&gt;Number of active TCP sessions: 405&lt;BR /&gt;Number of active UDP sessions: 275&lt;BR /&gt;Number of active ICMP sessions: 0&lt;BR /&gt;Number of active GTPc sessions: 0&lt;BR /&gt;Number of active HTTP2-5gc sessions: 0&lt;BR /&gt;Number of active GTPu sessions: 0&lt;BR /&gt;Number of pending GTPu sessions: 0&lt;BR /&gt;Number of active BCAST sessions: 0&lt;BR /&gt;Number of active MCAST sessions: 0&lt;BR /&gt;Number of active predict sessions: 0&lt;BR /&gt;Number of active SCTP sessions: 0&lt;BR /&gt;Number of active SCTP associations: 0&lt;BR /&gt;Session table utilization: 0%&lt;BR /&gt;Number of sessions created since bootup: 6168769&lt;BR /&gt;Packet rate: 1764/s&lt;BR /&gt;Throughput: 11728 kbps&lt;BR /&gt;New connection establish rate: 6 cps&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Session timeout&lt;BR /&gt;TCP default timeout: 3600 secs&lt;BR /&gt;TCP session timeout before SYN-ACK received: 5 secs&lt;BR /&gt;TCP session timeout before 3-way handshaking: 10 secs&lt;BR /&gt;TCP half-closed session timeout: 120 secs&lt;BR /&gt;TCP session timeout in TIME_WAIT: 15 secs&lt;BR /&gt;TCP session delayed ack timeout: 250 millisecs&lt;BR /&gt;TCP session timeout for unverified RST: 30 secs&lt;BR /&gt;UDP default timeout: 30 secs&lt;BR /&gt;ICMP default timeout: 6 secs&lt;BR /&gt;SCTP default timeout: 3600 secs&lt;BR /&gt;SCTP timeout before INIT-ACK received: 5 secs&lt;BR /&gt;SCTP timeout before COOKIE received: 60 secs&lt;BR /&gt;SCTP timeout before SHUTDOWN received: 30 secs&lt;BR /&gt;5GC delete timeout: 15 secs&lt;BR /&gt;other IP default timeout: 30 secs&lt;BR /&gt;Captive Portal session timeout: 30 secs&lt;BR /&gt;Session timeout in discard state:&lt;BR /&gt;TCP: 90 secs, UDP: 60 secs, SCTP: 60 secs, other IP protocols: 60 secs&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Session accelerated aging: True&lt;BR /&gt;Accelerated aging threshold: 80% of utilization&lt;BR /&gt;Scaling factor: 2 X&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Session setup&lt;BR /&gt;TCP - reject non-SYN first packet: True&lt;BR /&gt;Hardware session offloading: True&lt;BR /&gt;Hardware UDP session offloading: True&lt;BR /&gt;Tunnel acceleration: True&lt;BR /&gt;IPv6 firewalling: False&lt;BR /&gt;Strict TCP/IP checksum: True&lt;BR /&gt;Strict TCP RST sequence: True&lt;BR /&gt;Reject TCP small initial window: False&lt;BR /&gt;Reject TCP SYN with different seq/options: True&lt;BR /&gt;ICMP Unreachable Packet Rate: 200 pps&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Application trickling scan parameters:&lt;BR /&gt;Timeout to determine application trickling: 10 secs&lt;BR /&gt;Resource utilization threshold to start scan: 80%&lt;BR /&gt;Scan scaling factor over regular aging: 8&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Session behavior when resource limit is reached: drop&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Pcap token bucket rate : 10485760&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Max pending queued mcast packets per session : 0&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_0-1628835394873.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35689i38C01F9C3E411313/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_0-1628835394873.png" alt="BenPrice_0-1628835394873.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone seen such an issue before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Aug 2021 06:19:10 GMT</pubDate>
    <dc:creator>Ben-Price</dc:creator>
    <dc:date>2021-08-13T06:19:10Z</dc:date>
    <item>
      <title>User's in session table hitting wrong NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/426665#M94519</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a client that has several NAT rule's (as per below). The have discovered in the session table 2 IP's from the 10.128.48.0/22 subnet seem to be hitting &lt;EM&gt;'guest_nat'&lt;/EM&gt; rule below when they should be hitting the &lt;EM&gt;'users_nat' &lt;/EM&gt;rule below. When testing the NAT policy match with the affected IPs they hit the correct NAT rule (users_nat).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are currently migrating some of security policy rules to use group mappings, but I don't believe that would affect this in anyway, but could be wrong.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Affected IPs:&lt;/P&gt;&lt;P&gt;10.128.48.10/22&lt;/P&gt;&lt;P&gt;10.128.48.11/22&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@fw1(active)&amp;gt; test nat-policy-match protocol 6 from users to untrust source 10.128.48.11 destination 216.239.38.210 destination-port 443&lt;/P&gt;&lt;P&gt;Source-NAT: Rule matched: users_nat&lt;BR /&gt;10.128.48.11:0 =&amp;gt; 203.100.5.6:51317 (6),&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@fw1(active)&amp;gt; show running nat-policy &amp;lt;------ removed non relevant NAT policies&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;"users_nat; index: 16" {&lt;BR /&gt;nat-type ipv4;&lt;BR /&gt;from users;&lt;BR /&gt;source 10.128.48.0/22;&lt;BR /&gt;to untrust;&lt;BR /&gt;to-interface ;&lt;BR /&gt;destination any;&lt;BR /&gt;service 0:any/any/any;&lt;BR /&gt;translate-to "src: 203.100.5.6 (dynamic-ip-and-port) (pool idx: 1)";&lt;BR /&gt;terminal no;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;"guest_nat; index: 18" {&lt;BR /&gt;nat-type ipv4;&lt;BR /&gt;from guest;&lt;BR /&gt;source 10.128.16.0/20;&lt;BR /&gt;to untrust;&lt;BR /&gt;to-interface ;&lt;BR /&gt;destination any;&lt;BR /&gt;service 0:any/any/any;&lt;BR /&gt;translate-to "src: 203.100.5.6 (dynamic-ip-and-port) (pool idx: 1)";&lt;BR /&gt;terminal no;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@fw1(active)&amp;gt; show running nat-rule-ippool rule users_nat&lt;/P&gt;&lt;P&gt;VSYS 1 Rule users_nat:&lt;BR /&gt;Rule: users_nat, Pool index: 1, memory usage: 36472&lt;BR /&gt;-----------------------------------------&lt;BR /&gt;Oversubscription Ratio: 4&lt;BR /&gt;Number of Allocates: 367534&lt;BR /&gt;Last Allocated Index: 39302&lt;BR /&gt;-----------------------------------------&lt;BR /&gt;------------ Private Pool ---------------&lt;BR /&gt;Number of Allocates: 0&lt;BR /&gt;Last Allocated Index: 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@fw1(active)&amp;gt; show running nat-rule-ippool rule guest_nat&lt;/P&gt;&lt;P&gt;VSYS 1 Rule guest_nat:&lt;BR /&gt;Rule: guest_nat, Pool index: 1, memory usage: 36472&lt;BR /&gt;-----------------------------------------&lt;BR /&gt;Oversubscription Ratio: 4&lt;BR /&gt;Number of Allocates: 367552&lt;BR /&gt;Last Allocated Index: 54244&lt;BR /&gt;-----------------------------------------&lt;BR /&gt;------------ Private Pool ---------------&lt;BR /&gt;Number of Allocates: 0&lt;BR /&gt;Last Allocated Index: 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@fw1(active)&amp;gt; show running global-ippool&lt;/P&gt;&lt;P&gt;Idx Type From To ToNum Ref. Cnt Mem Size Ratio Ready&lt;BR /&gt;---- --------------- -------------------------------- --------------- ----- -------- -------- ----- ------&lt;BR /&gt;1 Dynamic IP/Port 10.128.48.0-10.128.51.255 203.100.5.6 1 4 36472 4 k1 /p1&lt;BR /&gt;2 Dynamic IP/Port 10.128.12.0-10.128.13.255 203.100.5.10 1 2 36472 4 k1 /p1&lt;BR /&gt;3 Dynamic IP/Port 10.0.98.0-10.0.98.255 203.100.5.7 1 2 36472 4 k1 /p1&lt;BR /&gt;4 Dynamic IP/Port 10.40.0.7-10.40.0.7 203.100.4.140 1 1 36472 4 k1 /p1&lt;BR /&gt;5 Dynamic IP/Port 10.0.35.0-10.0.35.255 203.100.4.142 1 1 36472 4 k1 /p1&lt;/P&gt;&lt;P&gt;Usable NAT DIP/DIPP shared memory size: 61785060&lt;BR /&gt;Used NAT DIP/DIPP shared memory size: 182360(0.30%)&lt;BR /&gt;Dynamic IP NAT Pool: 0(0.00%)&lt;BR /&gt;Dynamic IP/Port NAT Pool: 5(0.30%)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@fw1(active)&amp;gt; show session info&lt;/P&gt;&lt;P&gt;target-dp: *.dp0&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Number of sessions supported: 2097150&lt;BR /&gt;Number of allocated sessions: 692&lt;BR /&gt;Number of active TCP sessions: 405&lt;BR /&gt;Number of active UDP sessions: 275&lt;BR /&gt;Number of active ICMP sessions: 0&lt;BR /&gt;Number of active GTPc sessions: 0&lt;BR /&gt;Number of active HTTP2-5gc sessions: 0&lt;BR /&gt;Number of active GTPu sessions: 0&lt;BR /&gt;Number of pending GTPu sessions: 0&lt;BR /&gt;Number of active BCAST sessions: 0&lt;BR /&gt;Number of active MCAST sessions: 0&lt;BR /&gt;Number of active predict sessions: 0&lt;BR /&gt;Number of active SCTP sessions: 0&lt;BR /&gt;Number of active SCTP associations: 0&lt;BR /&gt;Session table utilization: 0%&lt;BR /&gt;Number of sessions created since bootup: 6168769&lt;BR /&gt;Packet rate: 1764/s&lt;BR /&gt;Throughput: 11728 kbps&lt;BR /&gt;New connection establish rate: 6 cps&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Session timeout&lt;BR /&gt;TCP default timeout: 3600 secs&lt;BR /&gt;TCP session timeout before SYN-ACK received: 5 secs&lt;BR /&gt;TCP session timeout before 3-way handshaking: 10 secs&lt;BR /&gt;TCP half-closed session timeout: 120 secs&lt;BR /&gt;TCP session timeout in TIME_WAIT: 15 secs&lt;BR /&gt;TCP session delayed ack timeout: 250 millisecs&lt;BR /&gt;TCP session timeout for unverified RST: 30 secs&lt;BR /&gt;UDP default timeout: 30 secs&lt;BR /&gt;ICMP default timeout: 6 secs&lt;BR /&gt;SCTP default timeout: 3600 secs&lt;BR /&gt;SCTP timeout before INIT-ACK received: 5 secs&lt;BR /&gt;SCTP timeout before COOKIE received: 60 secs&lt;BR /&gt;SCTP timeout before SHUTDOWN received: 30 secs&lt;BR /&gt;5GC delete timeout: 15 secs&lt;BR /&gt;other IP default timeout: 30 secs&lt;BR /&gt;Captive Portal session timeout: 30 secs&lt;BR /&gt;Session timeout in discard state:&lt;BR /&gt;TCP: 90 secs, UDP: 60 secs, SCTP: 60 secs, other IP protocols: 60 secs&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Session accelerated aging: True&lt;BR /&gt;Accelerated aging threshold: 80% of utilization&lt;BR /&gt;Scaling factor: 2 X&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Session setup&lt;BR /&gt;TCP - reject non-SYN first packet: True&lt;BR /&gt;Hardware session offloading: True&lt;BR /&gt;Hardware UDP session offloading: True&lt;BR /&gt;Tunnel acceleration: True&lt;BR /&gt;IPv6 firewalling: False&lt;BR /&gt;Strict TCP/IP checksum: True&lt;BR /&gt;Strict TCP RST sequence: True&lt;BR /&gt;Reject TCP small initial window: False&lt;BR /&gt;Reject TCP SYN with different seq/options: True&lt;BR /&gt;ICMP Unreachable Packet Rate: 200 pps&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Application trickling scan parameters:&lt;BR /&gt;Timeout to determine application trickling: 10 secs&lt;BR /&gt;Resource utilization threshold to start scan: 80%&lt;BR /&gt;Scan scaling factor over regular aging: 8&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Session behavior when resource limit is reached: drop&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Pcap token bucket rate : 10485760&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Max pending queued mcast packets per session : 0&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_0-1628835394873.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35689i38C01F9C3E411313/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_0-1628835394873.png" alt="BenPrice_0-1628835394873.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone seen such an issue before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 06:19:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/426665#M94519</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-08-13T06:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: User's in session table hitting wrong NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/426690#M94522</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I was surprized as well, I believe (not completete sure) it is "cosmetic bug" or should I say expected behaviour, due to the fact that both of your NAT rules are using same source translated address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you look closely to the output you provide you can see that both running nat-policy rules are saying they are using same pool idx: 1&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 08:54:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/426690#M94522</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2021-08-13T08:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: User's in session table hitting wrong NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/426719#M94528</link>
      <description>&lt;P&gt;Hi again &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I tried to replicate your case with virtual test FW, but I am not getting the same result (wrong nat rule in the session details).&lt;/P&gt;&lt;P&gt;Note: My test was with VM running 9.0.11&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-VM&amp;gt; show running nat-policy&lt;/P&gt;&lt;P&gt;"users; index: 1" {&lt;BR /&gt;nat-type ipv4;&lt;BR /&gt;from user;&lt;BR /&gt;source 10.10.10.0/24;&lt;BR /&gt;to untrust;&lt;BR /&gt;to-interface ;&lt;BR /&gt;destination any;&lt;BR /&gt;service 0:any/any/any;&lt;BR /&gt;translate-to "src: 20.20.20.3 (dynamic-ip-and-port)&lt;STRONG&gt;&lt;U&gt; (pool idx: 1)";&lt;/U&gt;&lt;/STRONG&gt;&lt;BR /&gt;terminal no;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;"guests; index: 2" {&lt;BR /&gt;nat-type ipv4;&lt;BR /&gt;from guests;&lt;BR /&gt;source 192.168.10.0/24;&lt;BR /&gt;to untrust;&lt;BR /&gt;to-interface ;&lt;BR /&gt;destination any;&lt;BR /&gt;service 0:any/any/any;&lt;BR /&gt;translate-to "src: 20.20.20.3 (dynamic-ip-and-port)&lt;U&gt;&lt;STRONG&gt; (pool idx: 1)";&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;terminal no;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-VM&amp;gt; show session id 132&lt;/P&gt;&lt;P&gt;Session 132&lt;/P&gt;&lt;P&gt;c2s flow:&lt;BR /&gt;source: 10.10.10.1 [user]&lt;BR /&gt;dst: 8.8.8.8&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 36651 dport: 22&lt;BR /&gt;state: INIT type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;/P&gt;&lt;P&gt;s2c flow:&lt;BR /&gt;source: 8.8.8.8 [untrust]&lt;BR /&gt;dst: 20.20.20.3&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 22 dport: 1484&lt;BR /&gt;state: INIT type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;/P&gt;&lt;P&gt;start time : Fri Aug 13 08:08:39 2021&lt;BR /&gt;timeout : 5 sec&lt;BR /&gt;total byte count(c2s) : 296&lt;BR /&gt;total byte count(s2c) : 0&lt;BR /&gt;layer7 packet count(c2s) : 4&lt;BR /&gt;layer7 packet count(s2c) : 0&lt;BR /&gt;vsys : vsys1&lt;BR /&gt;application : incomplete&lt;BR /&gt;rule : allow-all&lt;BR /&gt;service timeout override(index) : False&lt;BR /&gt;session to be logged at end : True&lt;BR /&gt;session in session ager : False&lt;BR /&gt;session updated by HA peer : False&lt;BR /&gt;address/port translation : source&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;nat-rule : users(vsys1)&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;layer7 processing : enabled&lt;BR /&gt;URL filtering enabled : False&lt;BR /&gt;session via syn-cookies : False&lt;BR /&gt;session terminated on host : True&lt;BR /&gt;session traverses tunnel : False&lt;BR /&gt;session terminate tunnel : False&lt;BR /&gt;captive portal session : False&lt;BR /&gt;ingress interface : ethernet1/1&lt;BR /&gt;egress interface : ethernet1/2&lt;BR /&gt;session QoS rule : N/A (class 4)&lt;BR /&gt;tracker stage firewall : Aged out&lt;BR /&gt;end-reason : aged-out&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Session 135&lt;/P&gt;&lt;P&gt;c2s flow:&lt;BR /&gt;source: 192.168.10.1 [guests]&lt;BR /&gt;dst: 8.8.8.8&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 49743 dport: 22&lt;BR /&gt;state: ACTIVE type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;/P&gt;&lt;P&gt;s2c flow:&lt;BR /&gt;source: 8.8.8.8 [untrust]&lt;BR /&gt;dst: 20.20.20.3&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 22 dport: 12242&lt;BR /&gt;state: ACTIVE type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;/P&gt;&lt;P&gt;start time : Fri Aug 13 08:09:36 2021&lt;BR /&gt;timeout : 5 sec&lt;BR /&gt;time to live : 1 sec&lt;BR /&gt;total byte count(c2s) : 222&lt;BR /&gt;total byte count(s2c) : 0&lt;BR /&gt;layer7 packet count(c2s) : 3&lt;BR /&gt;layer7 packet count(s2c) : 0&lt;BR /&gt;vsys : vsys1&lt;BR /&gt;application : undecided&lt;BR /&gt;rule : allow-all&lt;BR /&gt;service timeout override(index) : False&lt;BR /&gt;application db : 0&lt;BR /&gt;app.id : c2s node (0, 0) s2s node (0, 0)&lt;BR /&gt;session to be logged at end : True&lt;BR /&gt;session in session ager : True&lt;BR /&gt;session updated by HA peer : False&lt;BR /&gt;address/port translation : source&lt;BR /&gt;&lt;STRONG&gt;&lt;U&gt;nat-rule : guests(vsys1)&lt;/U&gt;&lt;/STRONG&gt;&lt;BR /&gt;layer7 processing : enabled&lt;BR /&gt;URL filtering enabled : False&lt;BR /&gt;session via syn-cookies : False&lt;BR /&gt;session terminated on host : True&lt;BR /&gt;session traverses tunnel : False&lt;BR /&gt;session terminate tunnel : False&lt;BR /&gt;captive portal session : False&lt;BR /&gt;ingress interface : ethernet1/3&lt;BR /&gt;egress interface : ethernet1/2&lt;BR /&gt;session QoS rule : N/A (class 4)&lt;BR /&gt;end-reason : unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately I don't have resources at the moment to have proper test (with established session), but I assume the result will be the same.&lt;/P&gt;&lt;P&gt;With above I would say:&lt;/P&gt;&lt;P&gt;- I still believe you see cosmetic bug. The correct NAT is used, but wrong nat name is logged. There is no way your traffic from users zone to hit rule with different source zone.&lt;/P&gt;&lt;P&gt;- What version are you running?&lt;/P&gt;&lt;P&gt;- Have you tried to set different source-translated address, just for a test?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 12:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/426719#M94528</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2021-08-13T12:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: User's in session table hitting wrong NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/427230#M94587</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@A_Astardzhiev&lt;/a&gt;&amp;nbsp;Thanks for testing. I have also run some basic testing in my lab with a similar scenario e.g. 2 internal subnets using dynamic IP and port using the same translated source address. When I ping a host on the internet the PAN session browser identifies the correct NAT rule to use.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client is running PAN OS 9.0.4, I am running an older version 8.1.19.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have asked them to try the below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;Kill the session for both of the affected IPs and then re-initiate it and see which NAT policy they hit (try this multiple times to see if they constantly hit the wrong rule)?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Disable the guest_nat policy and re-initiate host's connection and see if they can connect out and what the session browser indicates as per NAT policy?&lt;BR /&gt;&lt;BR /&gt;Change the source translated address on the guest_nat policy and see if the issue goes away or continues?&lt;BR /&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;It does seem to be looking as a cosmetic bug, as all other matching criteria match as per the outlined users_nat rule. I will revert once I have further info.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 17 Aug 2021 03:55:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/427230#M94587</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-08-17T03:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: User's in session table hitting wrong NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/432157#M95177</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@A_Astardzhiev&lt;/a&gt;&amp;nbsp;Thanks for your input here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It does look as though it was some sort of 'cosmetic bug', as you mentioned. We have not been able to replicate the issue, nor have seen any further incidents.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure if the pool idx number makes a difference, as you tested and I tested in my lab, I could not re-create the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have closed this case internally&amp;nbsp;for now and will keep an eye on it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 06:02:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-s-in-session-table-hitting-wrong-nat-rule/m-p/432157#M95177</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-09-07T06:02:12Z</dc:date>
    </item>
  </channel>
</rss>

