<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS NAT not coming back in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298519#M705</link>
    <description>&lt;P&gt;2 Thoughts.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Check your default route in the VR.&amp;nbsp; Ideally, you should use DHCP on both interfaces in the firewall and ensure to Uncheck "Automatically create default route..." on the Trust side Interface so that you only inherit the default route on E1/1.&lt;/LI&gt;&lt;LI&gt;Change the Source Translation in your NAT rule to:&amp;nbsp;&lt;UL&gt;&lt;LI&gt;Translation Type: DIPP&lt;/LI&gt;&lt;LI&gt;Address Type: Interface Address&lt;/LI&gt;&lt;LI&gt;Interface: ethernet 1/1&lt;/LI&gt;&lt;LI&gt;IP Address: None&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2019 12:30:35 GMT</pubDate>
    <dc:creator>jmeurer</dc:creator>
    <dc:date>2019-11-14T12:30:35Z</dc:date>
    <item>
      <title>AWS NAT not coming back</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298413#M704</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I tried to setup the nat, I can see my NAT and Security rule are being hit, but traffic is not flowing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bundle 1&lt;/P&gt;&lt;P&gt;Interface Swap (tested this with no swap too, and it didn;t work)&lt;/P&gt;&lt;P&gt;All of the 3 interfaces disabled src destination&lt;/P&gt;&lt;P&gt;all of them same sg, 0.0.0.0./0&lt;/P&gt;&lt;P&gt;eth0 and eth1 are on the same subnet (public) with a route 0.0.0.0/0 to igw&lt;/P&gt;&lt;P&gt;eth0 and eth1 both have a elastic ip attached&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;eth2 is on the private subnet, route 0.0.0.0/0 points to eth2&lt;/P&gt;&lt;P&gt;Server is on the same subnet as eth2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP seems to pick up the proper IPs (internal ips)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My nat rule&lt;/P&gt;&lt;P&gt;Source: Trust&amp;nbsp;-&amp;gt; Untrust&lt;BR /&gt;Destination ethernet1.1&lt;/P&gt;&lt;P&gt;source: any&lt;/P&gt;&lt;P&gt;destination: any&lt;/P&gt;&lt;P&gt;service any&lt;/P&gt;&lt;P&gt;Source Translation: dynamic ip and port &amp;lt;&amp;lt;PRIVATE IP ADDRESS of eth1&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hit count: over 2000+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my security rule&lt;/P&gt;&lt;P&gt;Universal, any, any, any .. any, allow. Hit count 3000+&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitor shows "aged out", allowed, so it the traffic flows one way, but it doesn't come back!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached is a screenshot, the internal machine (172.31.73.88 pings google&amp;nbsp;172.217.4.99&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;172.31.38.193 is my eth1 "untrust"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-13 at 10.03.52 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22328iE85E2931AFD6B951/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-11-13 at 10.03.52 PM.png" alt="Screen Shot 2019-11-13 at 10.03.52 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a request to google port 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-13 at 10.13.30 PM.png" style="width: 853px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22330i5BC333DA1960DF28/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-11-13 at 10.13.30 PM.png" alt="Screen Shot 2019-11-13 at 10.13.30 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-13 at 10.23.49 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22331iC9FEAD8C514834DF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-11-13 at 10.23.49 PM.png" alt="Screen Shot 2019-11-13 at 10.23.49 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 03:24:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298413#M704</guid>
      <dc:creator>nronica</dc:creator>
      <dc:date>2019-11-14T03:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: AWS NAT not coming back</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298519#M705</link>
      <description>&lt;P&gt;2 Thoughts.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Check your default route in the VR.&amp;nbsp; Ideally, you should use DHCP on both interfaces in the firewall and ensure to Uncheck "Automatically create default route..." on the Trust side Interface so that you only inherit the default route on E1/1.&lt;/LI&gt;&lt;LI&gt;Change the Source Translation in your NAT rule to:&amp;nbsp;&lt;UL&gt;&lt;LI&gt;Translation Type: DIPP&lt;/LI&gt;&lt;LI&gt;Address Type: Interface Address&lt;/LI&gt;&lt;LI&gt;Interface: ethernet 1/1&lt;/LI&gt;&lt;LI&gt;IP Address: None&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 12:30:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298519#M705</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-11-14T12:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: AWS NAT not coming back</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298520#M706</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I made those changes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The nat is working if the trust ENI is on the same subnet than the server I'm trying to nat.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any way I can point other route tables to this ENI? I made the change but they can't connect to internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 13:03:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298520#M706</guid>
      <dc:creator>nronica</dc:creator>
      <dc:date>2019-11-14T13:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: AWS NAT not coming back</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298528#M707</link>
      <description>&lt;P&gt;Excellent, that is a step in the right direction.&amp;nbsp; Create a static route on the firewall VR to send all of the VPC subnets that are behind the firewall out of the Eth1/2 interface to the first IP in the firewall's Trust Subnet.&amp;nbsp; AWS will then route it to the Server subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assume the Server subnet has a 0/0 route point to the Trust side of the firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 13:21:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298528#M707</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-11-14T13:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: AWS NAT not coming back</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298533#M708</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is how my network looks like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo in Public&lt;BR /&gt;A same subnet that the trust interface, works fine&lt;/P&gt;&lt;P&gt;B diff subnet,&amp;nbsp; same vpc, same Route Table, pointing to that ENI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-14 at 8.27.35 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22337i866B359FED93E19A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-11-14 at 8.27.35 AM.png" alt="Screen Shot 2019-11-14 at 8.27.35 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the route you mention, Unfortunately... I don't know how.. this is above the knowledge I have for this POC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is why I tried&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;172.31.0.0/16 is my VPC CIDR&lt;/P&gt;&lt;P&gt;172.31.38.193 is the private IP of the "non trust interface"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-14 at 8.30.43 AM.png" style="width: 701px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22338iF4D84A8AF54DFE41/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-11-14 at 8.30.43 AM.png" alt="Screen Shot 2019-11-14 at 8.30.43 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 13:32:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298533#M708</guid>
      <dc:creator>nronica</dc:creator>
      <dc:date>2019-11-14T13:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: AWS NAT not coming back</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298534#M709</link>
      <description>&lt;P&gt;Rather than specifying your Trust side IP of the firewall as the next hop in that route.&amp;nbsp; Set the next-hop IP to the first IP of the Trust subnet which is the AWS router IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ie. if the Trust subnet is /24, set the next-hop to&amp;nbsp;&lt;SPAN&gt;172.31.38.1&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 13:44:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298534#M709</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-11-14T13:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: AWS NAT not coming back</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298542#M710</link>
      <description>&lt;P&gt;what I learning experience!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My original routes&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-14 at 8.41.01 AM.png" style="width: 950px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22342iEEB627C8431AE634/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-11-14 at 8.41.01 AM.png" alt="Screen Shot 2019-11-14 at 8.41.01 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I added the VPC CIDR pointing to the "gateway of the trust interface" (Trust = 172.31.123.37)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-14 at 8.54.52 AM.png" style="width: 699px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22345i971E3E294F761830/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-11-14 at 8.54.52 AM.png" alt="Screen Shot 2019-11-14 at 8.54.52 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New route&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-14 at 8.51.57 AM.png" style="width: 656px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22344iAA3139C192697AC6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-11-14 at 8.51.57 AM.png" alt="Screen Shot 2019-11-14 at 8.51.57 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all your help, just documenting here if someone is on the same spot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 13:55:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/298542#M710</guid>
      <dc:creator>nronica</dc:creator>
      <dc:date>2019-11-14T13:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: AWS NAT not coming back</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/565377#M2029</link>
      <description>&lt;P&gt;Worked for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you !&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 15:06:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-nat-not-coming-back/m-p/565377#M2029</guid>
      <dc:creator>admin_missakid</dc:creator>
      <dc:date>2023-11-13T15:06:48Z</dc:date>
    </item>
  </channel>
</rss>

