NPTv6 seems bugged (PAN-OS 9.1.9)

cancel
Showing results for 
Search instead for 
Did you mean: 

NPTv6 seems bugged (PAN-OS 9.1.9)

L0 Member

Hi,

we're running into an issue with IPv6 NPTv6 which we use to route traffic through IPS on PA.

The address isn't translated as expected.

We tried NPTv6 in 2 configurations, both translate the same. We either used:

xxxx:xxxx:xxxx:ffe0::/60 -> xxxx:xxxx:xxxx:fff0::/60

or

xxxx:xxxx:xxxx:ffe3::/64 -> xxxx:xxxx:xxxx:fff3::/64

In both cases we sent traffic towards xxxx:xxxx:xxxx:ffe3:83:0:1:0 and it was translated by NPTv6 to xxxx:xxxx:xxxx:fff3:73:0:1:0.

 

Any ideas? Seems like a nasty bug.

 

Tried with 2 completely different source IPv6 addresses by the way, both translated the same with the 5th hextet being 0x10 lower than the original.

3 REPLIES 3

Community Team Member

Hi @Freaky ,

 

Not sure if this is a confirmed bug.

Have you verified the known issues in the OS release notes ? What's the OS version you're using ?

 

Cheers,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Don't forget to hit that Like button if a post is helpful to you!

L0 Member

Hi,

couldn't find it in the known issues nor in the fixed issues for 9.1.10.

As mentioned in the title it concerns 9.1.9 🙂

 

Thanks for the re'!

L0 Member

We reported this to our PA supplier by the way, don't have access to support myself.

Might take a while to propagate upstream.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!