← Network reference library

Wolex engineer reference · Security

NAT, zones & session troubleshooting

Track the original and translated tuples and avoid the common destination-NAT address-versus-zone mistake.

Download branded PDF

Revision 2.0 · Documentation reviewed 2026-10-10 · Original Wolex reference

Original tupleNAT ruleTranslated tupleReturn translation
Document both tuples and zones. A NAT translation changes addressing; it does not by itself authorize the application.

Quick reference

ItemRecordWhy it matters
Original flowSource / destination / portsRule match and original identity
Translated flowSource / destination / portsServer and return-path observations
NAT ruleOrdered first matching ruleShadowed rules may never apply
Security ruleAddresses plus effective zonesPermission is a separate decision
Return pathRoute back to translated sourceAsymmetry can bypass session state

What to understand first

01

Source NAT changes the source identity; destination NAT changes the destination. Port translation can change the transport tuple as well. Write the protocol and both ports, not just an IP pair.

02

For PAN-OS destination NAT, NAT-rule destination-zone matching follows the original destination route lookup. Security policy uses original addresses with post-NAT zones.

03

A first-match ordered NAT policy can select an unexpected earlier rule. Examine the actual session and applied translation instead of relying only on configuration intent.

04

Existing sessions, policy-based forwarding and routing context can affect observations. A new controlled attempt gives clearer evidence after a reviewed change.

Commands and interpretation

Inspection commands are read-only unless explicitly labeled otherwise. Capture commands start collection; configuration-mode commits change device state.

PAN-OS

Read-only operational

show session all filter source 198.51.100.10 destination 203.0.113.20
show session id <SESSION_ID>

Inspect: Read original and translated flows, rule, zones, application and byte counters; select the correct vsys.

Cisco IOS XE

Read-only EXEC

show ip nat translations
show ip nat statistics
show ip route 192.0.2.20

Inspect: Compare translation entries and counters with intended interfaces and the server route. NAT feature support varies.

Worked example · Illustrative, not a device capture

Illustrative inbound destination NAT

Original:   198.51.100.10 -> 203.0.113.20:443
Translated: 198.51.100.10 -> 192.0.2.20:443
Original destination zone: untrust
Server destination zone:   dmz

In this simplified PAN-OS example, the NAT rule matches the original destination route zone; the security rule targets dmz with the original destination address.

Server replies must follow a path that permits the firewall to apply the session translation. The documentation addresses are not deployment values.

Troubleshooting sequence

  1. Capture the original tuple, time and ingress zone of one failing attempt.
  2. Identify the first matching NAT rule and inspect the resulting session translation.
  3. Check security policy with original addresses and the effective destination zone.
  4. Verify server reachability and return routing for the translated source.
  5. Compare both flow directions and new-session logs after the approved correction.

Common mistakes

  • Assuming NAT implies an allow rule.
  • Using the private server address where a PAN-OS security rule requires the original destination.
  • Clearing all production sessions to test a single changed flow.

Acceptance checks

  • The intended rule and translation match a fresh session.
  • Forward and reverse counters move for the real application.
  • Adjacent applications and intended denies remain correct.

Primary references

Vendor documentation and protocol specifications support this guide. The diagrams, scenarios and troubleshooting sequences are Wolex-authored.