<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question regarding source NAT in S2S VPN in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/question-regarding-source-nat-in-s2s-vpn/m-p/615182#M4905</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/832439149"&gt;@shaq4242&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is correct.&amp;nbsp; You could even skip the source subnets if you want.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Sat, 26 Oct 2024 14:43:54 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-10-26T14:43:54Z</dc:date>
    <item>
      <title>Question regarding source NAT in S2S VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/question-regarding-source-nat-in-s2s-vpn/m-p/615119#M4904</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to create a S2S Tunnel to a customer. We need to reach 1 Server on their side (e.g. 192.168.100.1). The connection is needed from multiple Hosts from 2 different Subents on our Side (10.0.112.0/21 and 172.18.2.0/24). The customer does not want to allow both subnets instead they want to allow only 1 IP.&lt;/P&gt;&lt;P&gt;Now my question is: Is it possible to create a NAT Rule to do source NAT (Source Zone LAN, Source Adresses 10.0.150.0/24 and 172.18.2.0/24 --&amp;gt; Destination Zone VPN, Destination Address 192.168.100.1 --&amp;gt; Source Translation Dynamic IP and Port with IP e.g. 172.16.1.1. With that setup the customer only needs to allow the IP 172.16.1.1 inside the tunnel.&lt;/P&gt;&lt;P&gt;In my understanding this should work since it's the same sceanario as when multiple Hosts are going to the Internet with the same public IP, corect?&lt;/P&gt;&lt;P&gt;Thank you all!&lt;/P&gt;</description>
      <pubDate>Sat, 26 Oct 2024 11:24:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/question-regarding-source-nat-in-s2s-vpn/m-p/615119#M4904</guid>
      <dc:creator>shaq4242</dc:creator>
      <dc:date>2024-10-26T11:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding source NAT in S2S VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/question-regarding-source-nat-in-s2s-vpn/m-p/615182#M4905</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/832439149"&gt;@shaq4242&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is correct.&amp;nbsp; You could even skip the source subnets if you want.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 26 Oct 2024 14:43:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/question-regarding-source-nat-in-s2s-vpn/m-p/615182#M4905</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-10-26T14:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding source NAT in S2S VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/question-regarding-source-nat-in-s2s-vpn/m-p/1249013#M6736</link>
      <description>&lt;P&gt;Did this setup worked?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2026 01:41:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/question-regarding-source-nat-in-s2s-vpn/m-p/1249013#M6736</guid>
      <dc:creator>Glenyvie</dc:creator>
      <dc:date>2026-02-26T01:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding source NAT in S2S VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/question-regarding-source-nat-in-s2s-vpn/m-p/1249321#M6747</link>
      <description>&lt;P&gt;Yes — you absolutely can SNAT multiple internal subnets to a single IP inside the tunnel so the customer only allows one source IP.&lt;/P&gt;&lt;P&gt;It works exactly like Internet PAT logic, but inside the IPsec tunnel.&lt;/P&gt;&lt;P&gt;Additionally, you may create two separate NAT rules and perform static one-to-one NAT instead of dynamic IP and port if preferred.&lt;/P&gt;&lt;P&gt;Notes:&lt;/P&gt;&lt;P&gt;• The translated IP address must be included in the Phase 2 proxy IDs (local encryption domain).&lt;BR /&gt;• The peer must allow and route the translated IP inside the tunnel.&lt;BR /&gt;• The translated IP does not need to be an interface IP, but using a loopback or dedicated NAT IP range is considered best practice for design clarity&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 09:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/question-regarding-source-nat-in-s2s-vpn/m-p/1249321#M6747</guid>
      <dc:creator>abayoumi21</dc:creator>
      <dc:date>2026-03-03T09:19:43Z</dc:date>
    </item>
  </channel>
</rss>

