<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Config in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/nat-config/m-p/599083#M3818</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;In Checkp[oint we have an option to configure the dummy IPs in the NAT and use Proxy Arp to get it working. For example.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source: 10.10.10.1&lt;/P&gt;
&lt;P&gt;Destination: 10.100.100.1(Dummy IP)&lt;/P&gt;
&lt;P&gt;Translation:&lt;/P&gt;
&lt;P&gt;Source: 172.16.10.1(Dummy IP)&lt;/P&gt;
&lt;P&gt;Destination: 172.17.25.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And then configure the Proxy Arp and get this NAT working. This kind of NAT are used only to avoid overlapping subnets in the source and Destination end.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May i know how this can be achieved in PaloAlto? I dont really see such options on configuring dummy subnets in the NAT and get it working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2024 10:36:47 GMT</pubDate>
    <dc:creator>Sanjay_Ramaiah</dc:creator>
    <dc:date>2024-09-30T10:36:47Z</dc:date>
    <item>
      <title>NAT Config</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/nat-config/m-p/599083#M3818</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;In Checkp[oint we have an option to configure the dummy IPs in the NAT and use Proxy Arp to get it working. For example.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source: 10.10.10.1&lt;/P&gt;
&lt;P&gt;Destination: 10.100.100.1(Dummy IP)&lt;/P&gt;
&lt;P&gt;Translation:&lt;/P&gt;
&lt;P&gt;Source: 172.16.10.1(Dummy IP)&lt;/P&gt;
&lt;P&gt;Destination: 172.17.25.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And then configure the Proxy Arp and get this NAT working. This kind of NAT are used only to avoid overlapping subnets in the source and Destination end.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May i know how this can be achieved in PaloAlto? I dont really see such options on configuring dummy subnets in the NAT and get it working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 10:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/nat-config/m-p/599083#M3818</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2024-09-30T10:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Config</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/nat-config/m-p/599103#M3823</link>
      <description>&lt;P&gt;You are referring to traffic coming from Internet towards Palo?&lt;/P&gt;
&lt;P&gt;You can have dummy IP as destination IP if traffic arrives to Palo (destination mac address in the packet is mac of Palo wan interface).&lt;/P&gt;
&lt;P&gt;If traffic is not sent to Palo mac then for Palo to reply with proxy arp it needs IP to be configured on the wan interface (this check is strict starting from 10.2.8, before that it worked even without IP on wan interface).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/nat-policy-rules/proxy-arp-for-nat-address-pools" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/nat-policy-rules/proxy-arp-for-nat-address-pools&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 16:26:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/nat-config/m-p/599103#M3823</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-09-30T16:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Config</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/nat-config/m-p/599539#M3836</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;No that is not the scenario. We have to NAT both Source and destination to avoid overlapping.&lt;/P&gt;
&lt;P&gt;So it will be as below:&lt;/P&gt;
&lt;P&gt;Original:&lt;/P&gt;
&lt;P&gt;Source will have original IP&lt;/P&gt;
&lt;P&gt;Destination will be Dummy IP&lt;/P&gt;
&lt;P&gt;Tranlated:&lt;/P&gt;
&lt;P&gt;Source will be Natted to dummy IP&lt;/P&gt;
&lt;P&gt;Destination will translate to the original IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In checkpoint we use the interface that will respond to Dummy IP will have the MAC ID responding to the Original Destination.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 12:47:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/nat-config/m-p/599539#M3836</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2024-10-04T12:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Config</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/nat-config/m-p/599788#M3853</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I dont see the Dynamic NAT is working as expected. Basically Firewall is not proxing for the traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As i updated in the beginning here we need to NAT Source with the dummy range before reaching the destination. And Destination will be NATted with the dummy range.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From source side we will be pinging the Dummy Destination IP. In the Destination side we should be seeing the Dummy Source IP..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I reffered the Link and configured as same as that but it is still not working &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 14:36:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/nat-config/m-p/599788#M3853</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2024-10-08T14:36:42Z</dc:date>
    </item>
  </channel>
</rss>

