- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
03-25-2021 03:09 AM
We have 4 production servers are accessing ICMC service which is hosted in following URL “pubsub.googleapis.com”,
If all 4 servers in common NAT rule then there is a time-out error observed which caused ICMC service failure.
We have tried change the rule from FQDN and category based rule but still time-out noticed ,
Application team escalated to Google support ,though they are not able to find the root cause ,However ,Suggested to change TCP time wait session to 120 sec but it didn’t restore the failure.
As a workaround ,We assigned dedicated IP’s for each servers which resolve the issue.
Is there any way we could implement the NAT rule for these 4 servers, PAT is not working as well for this.
Thanks!
03-25-2021 07:19 AM
When you gave each server it's own IP address did you re-use the one that they were all trying to share at all? The thought process being that if you didn't, Google may simply be restricting the number of connections they are allowing from a single IP address for that service.
03-25-2021 07:59 AM
The IPs are one to one static public IP addresses configured and that is not we want.
03-26-2021 06:18 AM
The IPs are one to one static public IP addresses configured and that is not we want.
03-26-2021 01:55 PM
Did you try to increase the tcp timeout on the firewall as this could be the reason for the issue by creatinga custom service (also global session timeout or application override can be used by the service timeout is a better option)?
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRiCAK
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRiCAK
Just to know which timeout you are hiting use global counters with a filter:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS
From my point of view destination NAT with FQDN is still the best option for you:
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!