Hi all, I have the same problem with incomplete application. !Public zone! <====> PAN Firewall <====> INSIDE Firewall <-----> Server IP. I have nated Server IP to Public ip, and configure rule like the below. Name: (Ping) ; Src zone: (public); Src: (any); Dst zone: (any) ; Dst (any); Appliccation: (icmp, ping) ; Action: (ALLOW); I monitor traffic on PAN Firewall, I saw the traffic : Application is INCOMPLETE and action is ALLOW corresponding to the above "Ping" rule, and on my INSIDE Firewall, I also saw the traffic with the same public IP address to my server. I real don't know why is traffic pass into my INSIDE Firewall. Please help me to deny all of incomplete traffic. Thanks so much.
... View more