<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Tunnel IPSEC L2L VPN NAT not acting as intended in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-ipsec-l2l-vpn-nat-not-acting-as-intended/m-p/463185#M102335</link>
    <description>&lt;P&gt;I am Labbing up a configuration I am about to go live with in production but it is not acting as it should when trying to apply a NAT rule to a tunnel interface. When I apply individual rules to the vpn traffic as I would like it to act I am not getting the intended result. I have to select bi-direction to get the NAT rule to act as it should. It works that way but it bugs me on why it is not working as intdended.&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;Zones:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;WAN&lt;BR /&gt;VPN&lt;/P&gt;&lt;P&gt;LAB&lt;/P&gt;&lt;P&gt;NAT&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NAT Rules&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="11.11111111111111%"&gt;Name&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;Src Zone&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;Dest zone&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;dest int&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;src addr&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;dest adds&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;service&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;src translation&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;dest translation&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="11.11111111111111%"&gt;VPN-OUT&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;LAB&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;VPN&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;192.168.110.0/24&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;static-ip&amp;nbsp;&lt;BR /&gt;10.0.110.0/24&lt;BR /&gt;bi-directional: &lt;EM&gt;no&lt;/EM&gt;&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;none&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="11.11111111111111%"&gt;VPN-IN&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;VPN&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;VPN&amp;nbsp;&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;10.0.110.0/24&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;none&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;address 10.0.110.0/24&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;If I change bi-directional to yes on VPN out the both directions work. If I leave it as NO the traffic does not hit VPN-IN no matter what I do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestions of what is going on is greatly appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
    <pubDate>Thu, 03 Feb 2022 18:56:37 GMT</pubDate>
    <dc:creator>alliman</dc:creator>
    <dc:date>2022-02-03T18:56:37Z</dc:date>
    <item>
      <title>VPN Tunnel IPSEC L2L VPN NAT not acting as intended</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-ipsec-l2l-vpn-nat-not-acting-as-intended/m-p/463185#M102335</link>
      <description>&lt;P&gt;I am Labbing up a configuration I am about to go live with in production but it is not acting as it should when trying to apply a NAT rule to a tunnel interface. When I apply individual rules to the vpn traffic as I would like it to act I am not getting the intended result. I have to select bi-direction to get the NAT rule to act as it should. It works that way but it bugs me on why it is not working as intdended.&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;Zones:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;WAN&lt;BR /&gt;VPN&lt;/P&gt;&lt;P&gt;LAB&lt;/P&gt;&lt;P&gt;NAT&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NAT Rules&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="11.11111111111111%"&gt;Name&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;Src Zone&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;Dest zone&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;dest int&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;src addr&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;dest adds&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;service&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;src translation&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;dest translation&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="11.11111111111111%"&gt;VPN-OUT&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;LAB&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;VPN&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;192.168.110.0/24&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;static-ip&amp;nbsp;&lt;BR /&gt;10.0.110.0/24&lt;BR /&gt;bi-directional: &lt;EM&gt;no&lt;/EM&gt;&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;none&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="11.11111111111111%"&gt;VPN-IN&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;VPN&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;VPN&amp;nbsp;&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;10.0.110.0/24&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;any&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;none&lt;/TD&gt;&lt;TD width="11.11111111111111%"&gt;address 10.0.110.0/24&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;If I change bi-directional to yes on VPN out the both directions work. If I leave it as NO the traffic does not hit VPN-IN no matter what I do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestions of what is going on is greatly appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 18:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-ipsec-l2l-vpn-nat-not-acting-as-intended/m-p/463185#M102335</guid>
      <dc:creator>alliman</dc:creator>
      <dc:date>2022-02-03T18:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Tunnel IPSEC L2L VPN NAT not acting as intended</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-ipsec-l2l-vpn-nat-not-acting-as-intended/m-p/463232#M102341</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If you are using a bi-directional NAT. I would recommend you set it to yes. This prevent asymmetric routing and could cause applications to fail.&lt;/P&gt;
&lt;P&gt;Here is an article that may help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 21:14:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-ipsec-l2l-vpn-nat-not-acting-as-intended/m-p/463232#M102341</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-02-03T21:14:58Z</dc:date>
    </item>
  </channel>
</rss>

