Publishing website issue.

Announcements

Changes to the LIVEcommunity experience are coming soon... Here's what you need to know.

Reply
SamerKiwan
L2 Linker

Publishing website issue.

Hi Experts,

I am trying to publish a website, the webserver is behnid my Palo alto, i created NAT rule from public IP to be natted to the internal webserver IP address. What is starnge here is that i am not able to see my traffic when trying to reach the website from external. I was testing from my mobile so i put in Montior traffic tab source is my mobile public IP but couldnt find any logs:s.

Any suggestions?

Thanks,
Tags (2)
BPry
Cyber Elite

@SamerKiwan ,

Can you post your NAT rule so we can see how you've actually configured it? During testing also ensure that you've overrode the default security rules and enabled logging so that you actually get logs generated if you hit the interzone-default security entry. 

reaper
L7 Applicator

did you set your inbound NAT policy untrust to untrust, and your security policy untrust to dmz with the external IP as destination ?

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Brandon_Wertz
Cyber Elite

If you're able to get to the site, but not actually see the traffic in your traffic logs then I'm guessing the source IP and the Webstie are in the same zone and you're not logging "intrazone" traffic.

SamerKiwan
L2 Linker

Please find the NAT policy attached, and all my security policies are having logging enabled. 

 

Capture.JPG

SamerKiwan
L2 Linker

I tried all kinds of NAT policies and i tired the one you mentioned, but for some reason still no logs, maybe the issue is from public IP itself ? should i contact ISP to check with him?

SamerKiwan
L2 Linker

No Brandon i am not able to reach the website from external, i can only from internal network.

nanukanu
L2 Linker

Hi,

 

Why you don't create a rule from Outside to Outside with VIP as destination and DNAT of your internal IP? It must work.

 

How about you security rule? It is create Outside to Internal with VIP ip on destination field?

 

Regards,

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!