<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot reach server at DMZ via Nat in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455022#M101530</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT is setup at PA for outside users to reach DMZ server based on protocol&lt;BR /&gt;&lt;STRONG&gt;The topology is like the below:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SW1&lt;/STRONG&gt;(f1/1) -------- (e1/1,DMZ)&lt;STRONG&gt;PA&lt;/STRONG&gt;(Outside,e1/5)--------(f1/5)&lt;STRONG&gt;SW2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Interface config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;e1/1 10.100.255.1/24&lt;BR /&gt;f1/1 10.100.255.2/24 as inside Server&lt;/P&gt;&lt;P&gt;e1/5 44.33.22.1/24&lt;BR /&gt;f1/5 44.33.22.2/24 as outside Users&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please see below PA configurations for NAT and Security policy. SW2 can ping 44.33.22.1(PA), but&lt;STRONG&gt; cannot&lt;/STRONG&gt; ping translated ip address 44.33.22.10. We can also see Hit count increase at Nat, but not change at Security after SW2 ping 44.33.22.10. Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidyPalo_0-1640193938552.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38323iE9970A212E263AE6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DavidyPalo_0-1640193938552.png" alt="DavidyPalo_0-1640193938552.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidyPalo_1-1640192264988.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38318i887E80F0F28D6171/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DavidyPalo_1-1640192264988.png" alt="DavidyPalo_1-1640192264988.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidyPalo_2-1640192562824.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38319iD3C8ACC1ACF9C1C9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DavidyPalo_2-1640192562824.png" alt="DavidyPalo_2-1640192562824.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Dec 2021 18:27:13 GMT</pubDate>
    <dc:creator>DavidyPalo</dc:creator>
    <dc:date>2021-12-22T18:27:13Z</dc:date>
    <item>
      <title>Cannot reach server at DMZ via Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455022#M101530</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT is setup at PA for outside users to reach DMZ server based on protocol&lt;BR /&gt;&lt;STRONG&gt;The topology is like the below:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SW1&lt;/STRONG&gt;(f1/1) -------- (e1/1,DMZ)&lt;STRONG&gt;PA&lt;/STRONG&gt;(Outside,e1/5)--------(f1/5)&lt;STRONG&gt;SW2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Interface config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;e1/1 10.100.255.1/24&lt;BR /&gt;f1/1 10.100.255.2/24 as inside Server&lt;/P&gt;&lt;P&gt;e1/5 44.33.22.1/24&lt;BR /&gt;f1/5 44.33.22.2/24 as outside Users&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please see below PA configurations for NAT and Security policy. SW2 can ping 44.33.22.1(PA), but&lt;STRONG&gt; cannot&lt;/STRONG&gt; ping translated ip address 44.33.22.10. We can also see Hit count increase at Nat, but not change at Security after SW2 ping 44.33.22.10. Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidyPalo_0-1640193938552.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38323iE9970A212E263AE6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DavidyPalo_0-1640193938552.png" alt="DavidyPalo_0-1640193938552.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidyPalo_1-1640192264988.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38318i887E80F0F28D6171/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DavidyPalo_1-1640192264988.png" alt="DavidyPalo_1-1640192264988.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidyPalo_2-1640192562824.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38319iD3C8ACC1ACF9C1C9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DavidyPalo_2-1640192562824.png" alt="DavidyPalo_2-1640192562824.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 18:27:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455022#M101530</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2021-12-22T18:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot reach server at DMZ via Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455098#M101538</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Looks like your nat is incorrect, e.g. the zone. Its written as outside to outside. It should have the inside zone, DMZ as the destination zone. Unless its a bi-directional nat.&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 19:22:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455098#M101538</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-22T19:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot reach server at DMZ via Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455131#M101541</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What do the logs say? it should tell you if its allowed or denied.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 21:15:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455131#M101541</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-22T21:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot reach server at DMZ via Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455132#M101542</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Also do you have a NAT going outbound? From the DMZ server to the Internet?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 21:16:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455132#M101542</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-22T21:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot reach server at DMZ via Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455138#M101543</link>
      <description>&lt;P&gt;log says nothing. Please see the below. I setup log, but not sure if it can work.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidyPalo_0-1640208584733.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38330i9094F88370480914/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DavidyPalo_0-1640208584733.png" alt="DavidyPalo_0-1640208584733.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Also do you have a NAT going outbound? From the DMZ server to the Internet? . . . ."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Do you mean routing? The server and user pc have default gateway pointing at the PA. In addition to this, the PA still need to send something out? but the user pc is at the same subnet as PA interface e1/1, and the server is at the same subnet as PA e1/2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA still need routing?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 21:38:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455138#M101543</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2021-12-22T21:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot reach server at DMZ via Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455155#M101546</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I was looking at the screen shot above and I dont see a config for eth1/2. Also it you want the server to communicate out to the internet, it will need a NAT outbound. If the server and internal users are in different zones, you will need security policies to allow traffic from the users internal zone to the DNZ zone. If you want to do a hair-pin, e.g. the users get to the DNZ server via its public IP, you will need a u-turn NAT and policies for this.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEiCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEiCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perhaps I should have asked first, can you explain the traffic flow? How are the users supposed to access the server in the DMZ zone?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 22:26:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455155#M101546</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-22T22:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot reach server at DMZ via Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455156#M101547</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Also yes the PAN needs to have routing configured in its 'virtual router'. Has this been accomplioshed?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 22:28:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455156#M101547</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-22T22:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot reach server at DMZ via Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455168#M101549</link>
      <description>&lt;P&gt;&lt;SPAN&gt;"Also yes the PAN needs to have routing configured in its 'virtual router'. Has this been accomplioshed?. . . . "&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In routing field, for example, R1( orPC1) --------- Router2-------R3(PC2), when we need PC1 ping PC2, what we need to do is to configure local ip address and default-gateway or default ip route at PC1/PC2. and we do NOT need to configure additional routing at Router2. Only thing we need to do at Router2 is to setup two interfaces toward PC1 and PC2 respectively.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am not familiar with the firewall, but at this point, it should be similar with Router. PA should just setup virtual router in this case&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 03:19:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455168#M101549</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2021-12-23T03:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot reach server at DMZ via Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455246#M101557</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In the Palo Alto you do need to configure the routing in the scenario you proposed. So lets take that and here is what will need to be configured:&lt;/P&gt;
&lt;P&gt;PC1 = 192.168.1.5, 255.255.255.0, 192.168.1.1(Palo Alto interface VLAN10)&lt;/P&gt;
&lt;P&gt;PC2 = 192.168.2.5, 255.255.255.0, 192.168.2.1(Palo Alto interface VLAN20)&lt;/P&gt;
&lt;P&gt;Layer 2 interfaces&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_3-1640272995358.png" style="width: 724px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38345i6FA88D37C18BD047/image-dimensions/724x136?v=v2" width="724" height="136" role="button" title="OtakarKlier_3-1640272995358.png" alt="OtakarKlier_3-1640272995358.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Layer3 vlan interfaces&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_6-1640273484265.png" style="width: 718px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38348iF68815EE11177473/image-dimensions/718x70?v=v2" width="718" height="70" role="button" title="OtakarKlier_6-1640273484265.png" alt="OtakarKlier_6-1640273484265.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Virtual Router static routing&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_4-1640273131112.png" style="width: 714px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38346i3CA0E7DD1405FA8D/image-dimensions/714x72?v=v2" width="714" height="72" role="button" title="OtakarKlier_4-1640273131112.png" alt="OtakarKlier_4-1640273131112.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Security policies&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_5-1640273184116.png" style="width: 810px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38347i66FF350E6368C195/image-dimensions/810x57?v=v2" width="810" height="57" role="button" title="OtakarKlier_5-1640273184116.png" alt="OtakarKlier_5-1640273184116.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now this is the most basic configuration without any protections in place. It should allow you to ping from on PC to another.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 15:31:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455246#M101557</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-23T15:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot reach server at DMZ via Nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455398#M101574</link>
      <description>&lt;P&gt;Thank you!!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Dec 2021 22:34:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-reach-server-at-dmz-via-nat/m-p/455398#M101574</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2021-12-24T22:34:11Z</dc:date>
    </item>
  </channel>
</rss>

