Issue with ARP when using Bi-directional NAT with a Static Source Translation Address
31307
Created On 09/25/18 17:52 PM - Last Modified 05/01/25 22:41 PM
Symptom
In this configuration, the Palo Alto Networks device responds to an ARP reply from two different interfaces for the same IP. For Destination NAT, only the source zone and original un-translated IP address are checked to see if the parameters match the NAT rule.
Environment
- Palo Alto Firewalls
- PAN-OS 7.x
- Bidirectional NAT
Cause
- There is no check to see if the destination zone matches the rule since it will require an extra route lookup.
- If both zone interfaces can receive the ARP request, then both will respond with ARP reply.
Resolution
Additional Information
What does the Bi-Directional NAT Feature Provide?