<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Azure natting and routing of internet inbound via Palo? in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-natting-and-routing-of-internet-inbound-via-palo/m-p/306077#M740</link>
    <description>&lt;P&gt;My Azure subscription will be hosting public websites. Azure handles the translation between the assigned public and private IP addresses for each website.&amp;nbsp; My question concerns routing.&amp;nbsp; Say i have a VM 10.1.1.10/24. The 10.1.1.0/24 subnet has a UDR which will send internet-bound traffic out through my Palo.&amp;nbsp; But where can i assign a UDR for inbound traffic from internet to 10.1.1.10?&amp;nbsp; Currently Azure will route it directly. Can i apply a UDR somewhere to route inbound traffic via my Palo?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jan 2020 05:17:09 GMT</pubDate>
    <dc:creator>JimMcGrady</dc:creator>
    <dc:date>2020-01-09T05:17:09Z</dc:date>
    <item>
      <title>Azure natting and routing of internet inbound via Palo?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-natting-and-routing-of-internet-inbound-via-palo/m-p/306077#M740</link>
      <description>&lt;P&gt;My Azure subscription will be hosting public websites. Azure handles the translation between the assigned public and private IP addresses for each website.&amp;nbsp; My question concerns routing.&amp;nbsp; Say i have a VM 10.1.1.10/24. The 10.1.1.0/24 subnet has a UDR which will send internet-bound traffic out through my Palo.&amp;nbsp; But where can i assign a UDR for inbound traffic from internet to 10.1.1.10?&amp;nbsp; Currently Azure will route it directly. Can i apply a UDR somewhere to route inbound traffic via my Palo?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 05:17:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-natting-and-routing-of-internet-inbound-via-palo/m-p/306077#M740</guid>
      <dc:creator>JimMcGrady</dc:creator>
      <dc:date>2020-01-09T05:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Azure natting and routing of internet inbound via Palo?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-natting-and-routing-of-internet-inbound-via-palo/m-p/306089#M741</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;One option is to bind the public IPs (bound to the web-servers right now) to the outside (untrusted) interface of the firewall.&lt;/P&gt;&lt;P&gt;There might be other ways, but the one depicted above worked at least in my environment.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 08:24:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-natting-and-routing-of-internet-inbound-via-palo/m-p/306089#M741</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2020-01-09T08:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Azure natting and routing of internet inbound via Palo?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-natting-and-routing-of-internet-inbound-via-palo/m-p/336554#M866</link>
      <description>&lt;P&gt;A related question; If i have an Azure VM with IP 10.1.1.4, i can have it route via my PA firewall bidirectionally.&amp;nbsp; Outbound traffic from 10.1.1.4 would be source natted behind the firewall's public interface.&amp;nbsp; Inbound traffic would require a public IP on the firewall's public interface, or on an external load balancer in front of the firewall. A destination nat will deliver the inbound traffic to 10.1.1.4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But what happens if 10.1.1.4 is assigned a public IP in Azure? The Palo has no knowledge of this public IP and only handles the ranges it has routing for. Say public ip 13.75.5.5 has been assigned to 10.1.1.4.&amp;nbsp; Traffic to 13.75.5.5 will be translated by Azure to 10.1.1.4 and delivered directly to that VM. The VMs replies will come from 10.1.1.4 and route via the Palo. The Palo will see this as an asynchronous session and drop the traffic. Is this understanding correct?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 03:18:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-natting-and-routing-of-internet-inbound-via-palo/m-p/336554#M866</guid>
      <dc:creator>JimMcGrady</dc:creator>
      <dc:date>2020-07-03T03:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Azure natting and routing of internet inbound via Palo?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-natting-and-routing-of-internet-inbound-via-palo/m-p/336555#M867</link>
      <description>&lt;P&gt;Your understanding is spot on.&amp;nbsp; That PIP should be moved to the FW or ExtLB and natted to ensure proper bi-directional flow.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 03:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-natting-and-routing-of-internet-inbound-via-palo/m-p/336555#M867</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2020-07-03T03:41:16Z</dc:date>
    </item>
  </channel>
</rss>

