<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Source-NAT with POOL from GlobalProtect zone to subnet behind the MPLS router in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/source-nat-with-pool-from-globalprotect-zone-to-subnet-behind/m-p/517517#M3246</link>
    <description>&lt;P&gt;Hi community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm writting this post to get any ideas or suggestions in a new end-customer requirement. The main goal is that all clients connected via GlobalProtect can access to a new services acquired recently via MPLS (attached the brief topology). The point here is the MPLS's administrator share a specific IP Address that we need to NAT any source address from the Firewall Palo Alto.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We asigned the 192.168.130.0/24 pool to dynamic-client and we need to get access to 172.21.2.9 through out MPLS and it indicates us we have to NAT with 192.168.1.222 IP address; the config applied works, the traffic from the dynamic-client to 172.21.2.9 leave the firewall with 192.168.1.222 but, we can't connect and the session detail shows "application = incomplete/undecided"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the brief flow-traffic:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="larry2019_0-1665525816825.png" style="width: 565px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44586i06CCB4E876D5FC6D/image-dimensions/565x260/is-moderation-mode/true?v=v2" width="565" height="260" role="button" title="larry2019_0-1665525816825.png" alt="larry2019_0-1665525816825.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In advanced, thank you so much for your reply!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Oct 2022 22:05:45 GMT</pubDate>
    <dc:creator>larry2019</dc:creator>
    <dc:date>2022-10-11T22:05:45Z</dc:date>
    <item>
      <title>Source-NAT with POOL from GlobalProtect zone to subnet behind the MPLS router</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/source-nat-with-pool-from-globalprotect-zone-to-subnet-behind/m-p/517517#M3246</link>
      <description>&lt;P&gt;Hi community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm writting this post to get any ideas or suggestions in a new end-customer requirement. The main goal is that all clients connected via GlobalProtect can access to a new services acquired recently via MPLS (attached the brief topology). The point here is the MPLS's administrator share a specific IP Address that we need to NAT any source address from the Firewall Palo Alto.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We asigned the 192.168.130.0/24 pool to dynamic-client and we need to get access to 172.21.2.9 through out MPLS and it indicates us we have to NAT with 192.168.1.222 IP address; the config applied works, the traffic from the dynamic-client to 172.21.2.9 leave the firewall with 192.168.1.222 but, we can't connect and the session detail shows "application = incomplete/undecided"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the brief flow-traffic:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="larry2019_0-1665525816825.png" style="width: 565px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44586i06CCB4E876D5FC6D/image-dimensions/565x260/is-moderation-mode/true?v=v2" width="565" height="260" role="button" title="larry2019_0-1665525816825.png" alt="larry2019_0-1665525816825.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In advanced, thank you so much for your reply!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 22:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/source-nat-with-pool-from-globalprotect-zone-to-subnet-behind/m-p/517517#M3246</guid>
      <dc:creator>larry2019</dc:creator>
      <dc:date>2022-10-11T22:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Source-NAT with POOL from GlobalProtect zone to subnet behind the MPLS router</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/source-nat-with-pool-from-globalprotect-zone-to-subnet-behind/m-p/517699#M3257</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Make sure the policies are marked with 'Log at session end'. Then check the logs to see if any traffic is getting blocked. Could be a misconfigured security policy.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 21:08:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/source-nat-with-pool-from-globalprotect-zone-to-subnet-behind/m-p/517699#M3257</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-10-12T21:08:22Z</dc:date>
    </item>
  </channel>
</rss>

