<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: D-NAT not working in GCP in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518331#M1713</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi Fcrofdir,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for the hint.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;While troubleshooting we found, it was hitting default intrazone rule which was blocked.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Than we changed in the custom rule and it started working.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 09:07:10 GMT</pubDate>
    <dc:creator>Mitesh_Nandu</dc:creator>
    <dc:date>2022-10-19T09:07:10Z</dc:date>
    <item>
      <title>D-NAT not working in GCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518015#M1700</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have deployed PA-VM in GCP. In that we have configured 3 VPCs (MGMT, Untrust &amp;amp; Trust).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the Trust VPC we have created Windows Server 2016, in PA we created D-NAT &amp;amp; Security policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In GCP, Under Trust VPC Firewall Ingress traffic is allowed &amp;amp; Route is forwarded to PA-VM instance with 500 priority.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Untrust VPC - Firewall Ingress&amp;nbsp; traffic is allowed &amp;amp; Route is pointing toward default internet gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I am missing here ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Sun, 16 Oct 2022 13:27:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518015#M1700</guid>
      <dc:creator>Mitesh_Nandu</dc:creator>
      <dc:date>2022-10-16T13:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: D-NAT not working in GCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518021#M1701</link>
      <description>&lt;P&gt;have you look to your rooting table ? I assume that your wan and internal interface are in DHCP mode ?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2022 22:00:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518021#M1701</guid>
      <dc:creator>fcorfdir</dc:creator>
      <dc:date>2022-10-16T22:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: D-NAT not working in GCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518029#M1702</link>
      <description>&lt;P&gt;Hi Fcrofdir,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both interfaces is configured on static.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 02:29:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518029#M1702</guid>
      <dc:creator>Mitesh_Nandu</dc:creator>
      <dc:date>2022-10-17T02:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: D-NAT not working in GCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518034#M1703</link>
      <description>&lt;P&gt;does you create on the palo alto in trust vpc a route return to go back to the virtual router of the trust vpc.&lt;/P&gt;
&lt;P&gt;do you create a default route in the untrust to send traffic to the gcp virtual router of the untruste VPC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you capture packet il the logs of the palo when you try to send traffic to internet from your winodws server 2016. on the nat screenshot the hit count is "0" meening that no traffic hiting this rules. or maybe no traffic hitting the firewall VM&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 02:38:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518034#M1703</guid>
      <dc:creator>fcorfdir</dc:creator>
      <dc:date>2022-10-17T02:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: D-NAT not working in GCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518035#M1704</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Fcrofdir,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I performed the below steps in GCP:-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Created 3 VPCs (MGMT, TRUST &amp;amp; UNTRUST).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2.&amp;nbsp;&lt;/SPAN&gt;Create ingress/egress Firewall rules on the vpc networks.&lt;/P&gt;
&lt;P&gt;3. Modify the default route for the Trust network to use the Palo Alto instance.&lt;/P&gt;
&lt;P&gt;4. Created Trust VPC Network route in Untrust VPC to use PA instance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In PA performed below steps:-&lt;/P&gt;
&lt;P&gt;1. Assigned Static IP Address Interfaces.&lt;/P&gt;
&lt;P&gt;2. Created default route.&lt;/P&gt;
&lt;P&gt;3. Created Source NAT &amp;amp; Security Policy for Trust VPC Network.&lt;/P&gt;
&lt;P&gt;4. Created DNAT &amp;amp; Security Policy for Windows Server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly let me know which step I missed out.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 04:53:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518035#M1704</guid>
      <dc:creator>Mitesh_Nandu</dc:creator>
      <dc:date>2022-10-17T04:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: D-NAT not working in GCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518042#M1705</link>
      <description>&lt;P&gt;it sound Great.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you generate traffic from your Windows 2016 ? does it ping the PA trust interface ? do you see the traffic in the monitor traffic ? have you overide the intrazone default and teh intezone-default rulese in security policy to log fist packet and last.&lt;/P&gt;
&lt;P&gt;if the nat hit coult in nat&amp;nbsp; or the or security rules count don't increase that mind that there is something not working in the trust vpc config in GCP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I remember in AWS that you have to disable the change source destination check on the Network interface when you set the ip in static on a network interface. I d'ont remeber if you have to do something like that in GCP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 05:56:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518042#M1705</guid>
      <dc:creator>fcorfdir</dc:creator>
      <dc:date>2022-10-17T05:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: D-NAT not working in GCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518331#M1713</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Fcrofdir,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for the hint.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;While troubleshooting we found, it was hitting default intrazone rule which was blocked.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Than we changed in the custom rule and it started working.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 09:07:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/d-nat-not-working-in-gcp/m-p/518331#M1713</guid>
      <dc:creator>Mitesh_Nandu</dc:creator>
      <dc:date>2022-10-19T09:07:10Z</dc:date>
    </item>
  </channel>
</rss>

