Publishing website issue.

Reply
L2 Linker

Publishing website issue.

Hi Experts,

I am trying to publish a website, the webserver is behnid my Palo alto, i created NAT rule from public IP to be natted to the internal webserver IP address. What is starnge here is that i am not able to see my traffic when trying to reach the website from external. I was testing from my mobile so i put in Montior traffic tab source is my mobile public IP but couldnt find any logs:s.

Any suggestions?

Thanks,
Tags (2)
L7 Applicator

Re: Publishing website issue.

@SamerKiwan ,

Can you post your NAT rule so we can see how you've actually configured it? During testing also ensure that you've overrode the default security rules and enabled logging so that you actually get logs generated if you hit the interzone-default security entry. 

Community Manager

Re: Publishing website issue.

did you set your inbound NAT policy untrust to untrust, and your security policy untrust to dmz with the external IP as destination ?


Help the community: Like helpful comments and mark solutions
Reaper out
L6 Presenter

Re: Publishing website issue.

If you're able to get to the site, but not actually see the traffic in your traffic logs then I'm guessing the source IP and the Webstie are in the same zone and you're not logging "intrazone" traffic.

L2 Linker

Re: Publishing website issue.

Please find the NAT policy attached, and all my security policies are having logging enabled. 

 

Capture.JPG

L2 Linker

Re: Publishing website issue.

I tried all kinds of NAT policies and i tired the one you mentioned, but for some reason still no logs, maybe the issue is from public IP itself ? should i contact ISP to check with him?

L2 Linker

Re: Publishing website issue.

No Brandon i am not able to reach the website from external, i can only from internal network.

L2 Linker

Re: Publishing website issue.

Hi,

 

Why you don't create a rule from Outside to Outside with VIP as destination and DNAT of your internal IP? It must work.

 

How about you security rule? It is create Outside to Internal with VIP ip on destination field?

 

Regards,

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!