Public Inbound Traffic not hitting the firewall

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Public Inbound Traffic not hitting the firewall

L1 Bithead

Hi Team, I have set-up a Palo Alto appliance in Azure and i am trying to allow public access (RDP) to a server in Azure via the firewall. Here's what I have done:

  1. Attached a public IP to the Untrust interface of the Firewall (NSG attached to allow all traffic)
  2. Defined this Public IP in Untrust ethernet in the firewall
  3. Defined a NAT and security policy to allow natting to the private IP and these are correct (tested via GUI and SSH)

Now, the issue is when I try to RDP to the public IP, the traffic is not even hitting the firewall. Need urgent help on this. 




L2 Linker

The public IP should not be defined on the firewall.  The firewall interfaces should be configured for DHCP and have static assignments from the trust/untrust VNETS.


You can optionally have the firewall learn the default route via DHCP or configure it statically.

L0 Member
Ensure that the protocol is set to TCP not UDP. Confirm the TCP port is 3389.

I have this set-up in HA, if I enable DHCP, I cannot define IPs there in the interface.

It is set to any at this point. So, I don't think that should be the issue.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!