Inbound NAT with Port Redirection for port 443 using a single outside interface IP ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Inbound NAT with Port Redirection for port 443 using a single outside interface IP ?

L1 Bithead

My ISP only provides a single ip address for the outside interface via DHCP.

I would like to forward port 443 to and internal host, but Palo keeps dropping the packets.

 

It seems as if the device management restriction is responsible for this, but I have removed that policy from the external interface so I am not sure why this is getting filtered. See console message below.

Inbound rules are set to ANY and SSH port forwarding inbound works without any problem.

Packet drops were inspected with packet filtering so I know the packets are dropped by Palo. Packets (rx,fw,dr) increasing while no tx.

 

admin@PA1(active)> show counter global filter packet-filter yes delta yes

Global counters:
Elapsed time since last sampling: 45.132 seconds

name value rate severity category aspect description
--------------------------------------------------------------------------------
pkt_sent_host 6 0 info packet pktproc Packets successfully transmitted to host interface
session_allocated 6 0 info session resource Sessions allocated
session_installed 6 0 info session resource Sessions installed
session_discard 6 0 info session resource Session set to discard by security policy check
flow_host_pkt_xmt 27 0 info flow mgmt Packets transmitted to control plane
flow_host_service_deny 6 0 drop flow mgmt Device management session denied
flow_host_vardata_rate_limit_ok 27 0 info flow mgmt Host vardata not sent: rate limit ok
flow_ip_cksm_sw_validation 6 0 info flow pktproc Packets for which IP checksum validation was done in software
ha_msg_sent 15 0 info ha system HA: messages sent
ha_session_setup_msg_sent 6 0 info ha pktproc HA: session setup messages sent
ha_session_update_msg_sent 9 0 info ha pktproc HA: session update messages sent
--------------------------------------------------------------------------------
Total counters shown: 11
--------------------------------------------------------------------------------

admin@PA1(active)>

2 REPLIES 2

Cyber Elite
Cyber Elite

Can you share screenshot of your NAT and Security policy?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Thanks for the reply unfortunately, I couldn't share the live environment, so I labbed it out and it works well in the lab environment. Thanks for the reply though. 

  • 2639 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!