Problem with NAT

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Problem with NAT

L0 Member
I have an interface layer 3 on Palo Alto device with an IP public X.X.X.X connected to a router with IP public X.X.X.Y, I can ping the IP of the router, but from the router to the Palo Alto does not have ping, I have a profile of management that allows the ping, additionally has a NAT with the IP X.X.X.Z which is only used to go out to internet but also from the internet or the router does not reach the IP X.X.X.Z, but the machine that does NAT can out to the internet.
The question is the IP X.X.X.Z (NAT) it should come from the internet by ping or is normal behavior that is not reached by ping (not even from the Palo Alto where it is configured)?

This IP X.X.X.Z in the arp table appears as incomplete.

Cyber Elite
Cyber Elite

Do you have block any/any rule anywhere before intrazone-default?

What is result if you filter Monitor > Traffic

( addr.dst in X.X.X.X ) and ( app eq ping)


So in NAT rule you have only Source Translation configured?

If yes is bi-directional checked or not?


Screenshots maybe?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!