Quick reference
| Item | Record | Why it matters |
|---|---|---|
| Original flow | Source / destination / ports | Rule match and original identity |
| Translated flow | Source / destination / ports | Server and return-path observations |
| NAT rule | Ordered first matching rule | Shadowed rules may never apply |
| Security rule | Addresses plus effective zones | Permission is a separate decision |
| Return path | Route back to translated source | Asymmetry can bypass session state |
What to understand first
Source NAT changes the source identity; destination NAT changes the destination. Port translation can change the transport tuple as well. Write the protocol and both ports, not just an IP pair.
For PAN-OS destination NAT, NAT-rule destination-zone matching follows the original destination route lookup. Security policy uses original addresses with post-NAT zones.
A first-match ordered NAT policy can select an unexpected earlier rule. Examine the actual session and applied translation instead of relying only on configuration intent.
Existing sessions, policy-based forwarding and routing context can affect observations. A new controlled attempt gives clearer evidence after a reviewed change.
Commands and interpretation
Inspection commands are read-only unless explicitly labeled otherwise. Capture commands start collection; configuration-mode commits change device state.
PAN-OS
Read-only operational
show session all filter source 198.51.100.10 destination 203.0.113.20
show session id <SESSION_ID>Inspect: Read original and translated flows, rule, zones, application and byte counters; select the correct vsys.
Cisco IOS XE
Read-only EXEC
show ip nat translations
show ip nat statistics
show ip route 192.0.2.20Inspect: Compare translation entries and counters with intended interfaces and the server route. NAT feature support varies.
Worked example · Illustrative, not a device capture
Illustrative inbound destination NAT
Original: 198.51.100.10 -> 203.0.113.20:443
Translated: 198.51.100.10 -> 192.0.2.20:443
Original destination zone: untrust
Server destination zone: dmzIn this simplified PAN-OS example, the NAT rule matches the original destination route zone; the security rule targets dmz with the original destination address.
Server replies must follow a path that permits the firewall to apply the session translation. The documentation addresses are not deployment values.
Troubleshooting sequence
- Capture the original tuple, time and ingress zone of one failing attempt.
- Identify the first matching NAT rule and inspect the resulting session translation.
- Check security policy with original addresses and the effective destination zone.
- Verify server reachability and return routing for the translated source.
- Compare both flow directions and new-session logs after the approved correction.
Common mistakes
- Assuming NAT implies an allow rule.
- Using the private server address where a PAN-OS security rule requires the original destination.
- Clearing all production sessions to test a single changed flow.
Acceptance checks
- The intended rule and translation match a fresh session.
- Forward and reverse counters move for the real application.
- Adjacent applications and intended denies remain correct.
Primary references
Vendor documentation and protocol specifications support this guide. The diagrams, scenarios and troubleshooting sequences are Wolex-authored.
