<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can only access DMZ server using private address, U-turn NAT not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-only-access-dmz-server-using-private-address-u-turn-nat-not/m-p/514702#M106823</link>
    <description>&lt;P&gt;Configuring a new PA-850, new to this so go easy on me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have three zones, internal, outside, DMZ.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DMZ webserver&lt;/P&gt;
&lt;P&gt;Private IP = 192.168.2.16&lt;/P&gt;
&lt;P&gt;Public IP = 212.12.34.56&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created two NAT rules as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;internal u-turn to DMZ&lt;/P&gt;
&lt;P&gt;source zone = internal&lt;/P&gt;
&lt;P&gt;dest zone = outside&lt;/P&gt;
&lt;P&gt;dest address = 212.12.34.56&lt;/P&gt;
&lt;P&gt;dest translated address = 192.168.2.16&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;external to DMZ&lt;/P&gt;
&lt;P&gt;source zone = any&lt;/P&gt;
&lt;P&gt;dest one = outside&lt;/P&gt;
&lt;P&gt;dest address = 212.12.34.56&lt;/P&gt;
&lt;P&gt;dest translated address = 192.168.2.16&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For purposes of testing this is working I have created a security rule of ANY ANY.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can only view the webserver from the internal network using the internal IP address of 192.168.2.16, using the FQDN or public IP I only get timeouts.&amp;nbsp; Wireshark on the internal clients show outbound HTTP but Wireshark on the server shows no traffic inbound except when using 192.168.2.16.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The u-turn NAT rule is above the public NAT rule and the hide-NAT rule is last in the list.&amp;nbsp; I am sure I am missing something simple but I have been through the how to u-turn video and guide here: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEiCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEiCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only thing I can see is there is also some source translation in the video which is not shown in the document but I think that is a red herring.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
    <pubDate>Tue, 13 Sep 2022 10:19:56 GMT</pubDate>
    <dc:creator>WilliamD</dc:creator>
    <dc:date>2022-09-13T10:19:56Z</dc:date>
    <item>
      <title>Can only access DMZ server using private address, U-turn NAT not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-only-access-dmz-server-using-private-address-u-turn-nat-not/m-p/514702#M106823</link>
      <description>&lt;P&gt;Configuring a new PA-850, new to this so go easy on me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have three zones, internal, outside, DMZ.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DMZ webserver&lt;/P&gt;
&lt;P&gt;Private IP = 192.168.2.16&lt;/P&gt;
&lt;P&gt;Public IP = 212.12.34.56&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created two NAT rules as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;internal u-turn to DMZ&lt;/P&gt;
&lt;P&gt;source zone = internal&lt;/P&gt;
&lt;P&gt;dest zone = outside&lt;/P&gt;
&lt;P&gt;dest address = 212.12.34.56&lt;/P&gt;
&lt;P&gt;dest translated address = 192.168.2.16&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;external to DMZ&lt;/P&gt;
&lt;P&gt;source zone = any&lt;/P&gt;
&lt;P&gt;dest one = outside&lt;/P&gt;
&lt;P&gt;dest address = 212.12.34.56&lt;/P&gt;
&lt;P&gt;dest translated address = 192.168.2.16&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For purposes of testing this is working I have created a security rule of ANY ANY.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can only view the webserver from the internal network using the internal IP address of 192.168.2.16, using the FQDN or public IP I only get timeouts.&amp;nbsp; Wireshark on the internal clients show outbound HTTP but Wireshark on the server shows no traffic inbound except when using 192.168.2.16.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The u-turn NAT rule is above the public NAT rule and the hide-NAT rule is last in the list.&amp;nbsp; I am sure I am missing something simple but I have been through the how to u-turn video and guide here: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEiCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEiCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only thing I can see is there is also some source translation in the video which is not shown in the document but I think that is a red herring.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 10:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-only-access-dmz-server-using-private-address-u-turn-nat-not/m-p/514702#M106823</guid>
      <dc:creator>WilliamD</dc:creator>
      <dc:date>2022-09-13T10:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can only access DMZ server using private address, U-turn NAT not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-only-access-dmz-server-using-private-address-u-turn-nat-not/m-p/514748#M106829</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Make sure you have logging enabled on your policies and see where the traffic is flowing. I know you have your any any policy, but it might not be setup correctly. The thought I had was possible asymmetric routing. So check your virtual router and make sure everything is getting routed correctly.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 19:10:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-only-access-dmz-server-using-private-address-u-turn-nat-not/m-p/514748#M106829</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-09-13T19:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can only access DMZ server using private address, U-turn NAT not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-only-access-dmz-server-using-private-address-u-turn-nat-not/m-p/514815#M106845</link>
      <description>&lt;P&gt;Plugging in the Outside interface into a small switch brought the interface up and the translation between internal and DMZ then occurred as expected.&amp;nbsp; I don't remember seeing anything about this in the documentation but I guess a one-liner I may have missed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for posting back OtakarKlier I did learn how to use the monitor a little so it wasn't a waste of time.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 12:25:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-only-access-dmz-server-using-private-address-u-turn-nat-not/m-p/514815#M106845</guid>
      <dc:creator>WilliamD</dc:creator>
      <dc:date>2022-09-14T12:25:31Z</dc:date>
    </item>
  </channel>
</rss>

