Result of the command: "packet-tracer input t1 tcp 8.8.8.8 80 139.55.206.123 80" Phase: 1 Type: UN-NAT Subtype: static Result: ALLOW Config: object network t1-citrix-http nat (servers,t1) static 139.55.206.123 service tcp www www Additional Information: NAT divert to egress interface servers Untranslate 139.55.206.123/80 to 192.168.2.20/80 Phase: 2 Type: ACCESS-LIST Subtype: log Result: ALLOW Config: access-group t1_access_in in interface t1 access-list t1_access_in extended permit tcp any object lsf-ctx object-group DM_INLINE_TCP_4 object-group service DM_INLINE_TCP_4 tcp port-object range 2598 2601 port-object eq citrix-ica port-object eq www port-object eq https Additional Information: Phase: 3 Type: NAT Subtype: per-session Result: ALLOW Config: Additional Information: Phase: 4 Type: IP-OPTIONS Subtype: Result: ALLOW Config: Additional Information: Phase: 5 Type: VPN Subtype: ipsec-tunnel-flow Result: ALLOW Config: Additional Information: Phase: 6 Type: NAT Subtype: rpf-check Result: ALLOW Config: nat (servers,t1) source dynamic any interface Additional Information: Phase: 7 Type: NAT Subtype: per-session Result: ALLOW Config: Additional Information: Phase: 8 Type: IP-OPTIONS Subtype: Result: ALLOW Config: Additional Information: Phase: 9 Type: FLOW-CREATION Subtype: Result: ALLOW Config: Additional Information: New flow created with id 27320, packet dispatched to next module Result: input-interface: t1 input-status: up input-line-status: up output-interface: servers output-status: up output-line-status: up Action: allow