<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto CGNAT block issues with GeoBlock rule in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-cgnat-block-issues-with-geoblock-rule/m-p/1240998#M6418</link>
    <description>&lt;P&gt;We just migrationed from Cisco Firepower:&lt;/P&gt;
&lt;P&gt;We have some Negate Geo block rules that will block any country that is NOT on the lists of allowed, but now it is unintentinally blocking CGNAT addresses. We would still like to only allow US CGNAT's but the fix below would be world wide I believe? We don't want to wait until someone travels around the US and runs into the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This would also Apply to Employee and Public accesss as they both would be geo blocked. So Vpn isnt a final fix.&lt;/P&gt;
&lt;P&gt;Is there any other way around having to add the100.64.0.0/10 block ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How are others dealing with CGNAT's?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Oct 2025 16:12:08 GMT</pubDate>
    <dc:creator>E.Egger</dc:creator>
    <dc:date>2025-10-30T16:12:08Z</dc:date>
    <item>
      <title>Palo Alto CGNAT block issues with GeoBlock rule</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-cgnat-block-issues-with-geoblock-rule/m-p/1240998#M6418</link>
      <description>&lt;P&gt;We just migrationed from Cisco Firepower:&lt;/P&gt;
&lt;P&gt;We have some Negate Geo block rules that will block any country that is NOT on the lists of allowed, but now it is unintentinally blocking CGNAT addresses. We would still like to only allow US CGNAT's but the fix below would be world wide I believe? We don't want to wait until someone travels around the US and runs into the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This would also Apply to Employee and Public accesss as they both would be geo blocked. So Vpn isnt a final fix.&lt;/P&gt;
&lt;P&gt;Is there any other way around having to add the100.64.0.0/10 block ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How are others dealing with CGNAT's?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 16:12:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-cgnat-block-issues-with-geoblock-rule/m-p/1240998#M6418</guid>
      <dc:creator>E.Egger</dc:creator>
      <dc:date>2025-10-30T16:12:08Z</dc:date>
    </item>
  </channel>
</rss>

