Dropped Traffic

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Dropped Traffic

L2 Linker

We have PA3000 running 7.1.10

I have issue where tarffic is being droped by the Deny All rule , the last rule even though I have allowed this tarffic to come in ext zone ext zone.

Also for some reason the destination seems to be Internal where as the interafce is the public one.


Does any one have an explanation




Accepted Solutions

Yes this rule is the isue.

If you need only limited ports to NAT to internal host then change service Any to tcp/80 or whatever port you need.


Or clone this NAT rule.

Move clone rule above it.

Change cloned rule to add service udp/500 and clear out Destination Address Translation under "Translated Packet" tab.

This will exclude incoming IPSec from DNAT.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post


L7 Applicator

Check if you accidentally apply NAT to traffic that hits your public IP 212.240.x.x port 500.

Maybe you have one-to-one NAT to some internal IP.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011


I do have the follwing NAT on the public IP . Is the any service the  issue ? The transalated packet goes to a internal host





The any service wouldn't really be an issue. Maybe take a screenshot of the actual policy in the NAT policy screen instead of this section. If you have the NAT configured bi-directional: yes then you could potentially see exactly what you are describing, as the destination interface then would come across as whatever zone that original source address actually resides in. 

This is screen shot from the NAT Policy screen .

There is alos another NAT policy the other way for this IP , so we do have a bi-directionl NAT


Does this NAT policy not imply that all traffic comeing into this IP is NAted to internal IP

I only have a rule to allow public ip , ext zone > my public ip ext zone for ipsec and IKE. 


This is being denied by my Deny All rule , I assume becasue the FW is only seeing the NAted destination (internal) becasue NAT is done before the FW Rules are hit ?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!