A destination NAT rule can match while the application remains unreachable: translation and permission are separate decisions on a Palo Alto Networks firewall.[1] Before widening a Security rule, prove which address, zone and return path the failing connection actually uses.
This guide answers a specific troubleshooting question: why does Palo Alto destination NAT match, but the connection still fail? It includes a policy worksheet, a symptom-to-test matrix and an acceptance checklist you can reuse during a change. The example is hypothetical, uses symbolic objects rather than production addresses, and does not claim a firewall lab run.