An engineer is troubleshooting a case where users on a specific subnet cannot reach a web server behind a Palo Alto Networks firewall. The security policy allows the traffic, and the firewall sees the session hit the rule. However, the server does not receive the request. What is the most likely cause?
Trap 1: Session offload is causing the packet to bypass security checks
Session offload is for performance and would not prevent the server from receiving the request.
Trap 2: The firewall is unable to resolve the destination MAC address
This would cause no traffic, but the firewall sees the session; MAC resolution is usually fine.
Trap 3: The destination NAT is misconfigured
If policy allows and session is seen, NAT is likely working; the server not receiving suggests a routing issue.
- A
Session offload is causing the packet to bypass security checks
Why it fails: Session offload is for performance and would not prevent the server from receiving the request.
- B
The firewall is unable to resolve the destination MAC address
Why it fails: This would cause no traffic, but the firewall sees the session; MAC resolution is usually fine.
- C
Asymmetric routing causes the firewall to drop the SYN packet
The firewall permits the session, but the SYN arrives on one interface while return traffic would egress a different path. Palo Alto Networks firewalls drop packets failing the reverse path forwarding check, so the server never receives the request despite the matching allow rule.
- D
The destination NAT is misconfigured
Why it fails: If policy allows and session is seen, NAT is likely working; the server not receiving suggests a routing issue.