Hi NAT is setup at PA for outside users to reach DMZ server based on protocol The topology is like the below: SW1(f1/1) -------- (e1/1,DMZ)PA(Outside,e1/5)--------(f1/5)SW2 Interface config: e1/1 10.100.255.1/24 f1/1 10.100.255.2/24 as inside Server e1/5 44.33.22.1/24 f1/5 44.33.22.2/24 as outside Users Please see below PA configurations for NAT and Security policy. SW2 can ping 44.33.22.1(PA), but cannot ping translated ip address 44.33.22.10. We can also see Hit count increase at Nat, but not change at Security after SW2 ping 44.33.22.10. Thank you
... View more