Hello, I have a FW that has many nat rules. And I found a bug, pan-130550: ( PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls ) For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation. Workaround: Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic. Mine is PA-5250 and I already have DIP NAT rules for inter vsys traffic, and it looks like working well(hit counts, log..) Anyone knows about that bug? Does it impact on every traffic or sometimes FW cannot perform NAT? The workaround of the bug not works for me, I can't convert every DIP NAT rule to DIPP in my FW...
... View more