<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNAT to a FQDN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520474#M107857</link>
    <description>&lt;P&gt;Good morning,&lt;/P&gt;
&lt;P&gt;thanks for your feedbacks.&lt;/P&gt;
&lt;P&gt;Maybe i´ve to explain it a little more&lt;/P&gt;
&lt;P&gt;In my testlab i have a dynamic IP from my provider.&lt;/P&gt;
&lt;P&gt;In front of the Palo ther is another Router, connecting to the Internet&lt;/P&gt;
&lt;P&gt;Normaly i would change the router to Modem only, but there a my also my Telef´phones connected, so i cant switch it&lt;/P&gt;
&lt;P&gt;I read some different posts about Source NAT to get the external IP with a DynDNS service&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.wirelessphreak.com/2019/01/pan-firewall-and-xbox-nat.html" target="_blank"&gt;https://www.wirelessphreak.com/2019/01/pan-firewall-and-xbox-nat.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/dynamic-ip-isp-nat/td-p/103703" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/dynamic-ip-isp-nat/td-p/103703&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What i understand:&lt;/P&gt;
&lt;P&gt;I need to SNAT the traffic from the internal host to my external IP&lt;/P&gt;
&lt;P&gt;I need to NAT the traffic coming from external to my internal host&lt;/P&gt;
&lt;P&gt;In the LAB this are two services&lt;/P&gt;
&lt;P&gt;The Xboxes&lt;/P&gt;
&lt;P&gt;And a acme bot for lets encrypt certificates&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2022 07:17:44 GMT</pubDate>
    <dc:creator>maniac72</dc:creator>
    <dc:date>2022-11-07T07:17:44Z</dc:date>
    <item>
      <title>SNAT to a FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/518549#M107574</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to create a NAT policy that would NAT traffic from my internal Zone to and update server.&lt;/P&gt;
&lt;P&gt;the problem is i have FQDN of destination server which resolves to multiple different IPs.&lt;/P&gt;
&lt;P&gt;I need to find a way to complete this NAT policy, is there any way i can make this work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 18:38:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/518549#M107574</guid>
      <dc:creator>mike.07</dc:creator>
      <dc:date>2022-10-20T18:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: SNAT to a FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/519013#M107645</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/247068"&gt;@mike.07&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the NAT rule, you can specify an FQDN as an object just as long as the Palo can resolve the FQDN.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 10:14:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/519013#M107645</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2022-10-25T10:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: SNAT to a FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520270#M107829</link>
      <description>&lt;P&gt;Hello, im a new PaloAlto User and run in some problems too.&lt;/P&gt;
&lt;P&gt;For testlab i need fqdn Source NAT.&lt;/P&gt;
&lt;P&gt;But i cant use the Adress added at "Adresses" and add it as a source at NAT...&lt;/P&gt;
&lt;P&gt;PA can resolve the FQDN.&lt;/P&gt;
&lt;P&gt;Anything im missing?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo1_Adresses.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45149i56A05E5A6D7087E9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="palo1_Adresses.jpg" alt="palo1_Adresses.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo1_SourceNAT.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45150i18891FE72BEA36B0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="palo1_SourceNAT.jpg" alt="palo1_SourceNAT.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 07:06:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520270#M107829</guid>
      <dc:creator>maniac72</dc:creator>
      <dc:date>2022-11-04T07:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: SNAT to a FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520274#M107830</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/255129"&gt;@maniac72&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you have a little wrong concepto to apply NAT in Palo Alto.&lt;/P&gt;
&lt;P&gt;I suggest review this links:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/nat/nat-configuration-examples&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;https://www.packetswitch.co.uk/palo-alto-nat-example/&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 08:07:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520274#M107830</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2022-11-04T08:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: SNAT to a FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520390#M107845</link>
      <description>&lt;P&gt;Hello:&lt;/P&gt;
&lt;P&gt;I understand more or less what you want or wish to do as a goal:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you create as Address type FQDN, you place the subdomain and Palo Alto will be in charge of resolving at DNS level. That if the Palo Alto must be able to connect with one or two DNS servers, to be able to resolve these addresses. If the Palo Alto does not have DNS set up it will not be able to resolve these addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand that what you want is that when traffic goes to a certain destination, example a FQDN, example:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.testingfqdn.com" target="_blank"&gt;www.testingfqdn.com&lt;/A&gt; ----&amp;gt; 1.2.3.4/32&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Well if that is what you want to do, when it goes to that destination apply a Source NAT, what you should do is the following:&lt;/P&gt;
&lt;P&gt;First, you must set the corresponding zones, source, e.g. your network/LAN zone, destination your outside/Untrust Internet zone. Now in the original packet section, in destination, instead of any, put your FQDN. Now in the translation section, in the "Source translation" section, enter the IP with which you are going to translate the traffic, e.g. the outgoing interface, if it were a public IP, then select the Untrust interface and the Public IP of your interface.&lt;/P&gt;
&lt;P&gt;Now if you are looking to do a DNAT or PortForwarding the configuration is somewhat different.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are a couple of sites/links to guide and support you:&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/nat/nat-configuration-examples&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;https://www.packetswitch.co.uk/palo-alto-nat-example/&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 20:50:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520390#M107845</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2022-11-04T20:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: SNAT to a FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520474#M107857</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;
&lt;P&gt;thanks for your feedbacks.&lt;/P&gt;
&lt;P&gt;Maybe i´ve to explain it a little more&lt;/P&gt;
&lt;P&gt;In my testlab i have a dynamic IP from my provider.&lt;/P&gt;
&lt;P&gt;In front of the Palo ther is another Router, connecting to the Internet&lt;/P&gt;
&lt;P&gt;Normaly i would change the router to Modem only, but there a my also my Telef´phones connected, so i cant switch it&lt;/P&gt;
&lt;P&gt;I read some different posts about Source NAT to get the external IP with a DynDNS service&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.wirelessphreak.com/2019/01/pan-firewall-and-xbox-nat.html" target="_blank"&gt;https://www.wirelessphreak.com/2019/01/pan-firewall-and-xbox-nat.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/dynamic-ip-isp-nat/td-p/103703" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/dynamic-ip-isp-nat/td-p/103703&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What i understand:&lt;/P&gt;
&lt;P&gt;I need to SNAT the traffic from the internal host to my external IP&lt;/P&gt;
&lt;P&gt;I need to NAT the traffic coming from external to my internal host&lt;/P&gt;
&lt;P&gt;In the LAB this are two services&lt;/P&gt;
&lt;P&gt;The Xboxes&lt;/P&gt;
&lt;P&gt;And a acme bot for lets encrypt certificates&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 07:17:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520474#M107857</guid>
      <dc:creator>maniac72</dc:creator>
      <dc:date>2022-11-07T07:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: SNAT to a FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520475#M107858</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/255129"&gt;@maniac72&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;OK ok, that's another thing.&lt;/P&gt;
&lt;P&gt;Yes I have implemented scenarios with DYNDNS, for example Palo Alto's Global Protect VPN service.&lt;/P&gt;
&lt;P&gt;So if for some reason, you need to expose your xbox among other equipment to be accessed from the Internet, but you don't have a Static Public IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recommend:&lt;/P&gt;
&lt;P&gt;On the modem, configure the DYNDNS service so that the Modem, which has dynamic Public IP addressing, publishes and updates the IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now with that done, in the same ISP modem, you can configure a DMZ or Port Mapping specific to a certain IP/Ports will be, the External interface of your Palo Alto, which I imagine has an IP in the same LAN range, of your Modem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Well then it looks like this:&lt;/P&gt;
&lt;P&gt;IPdynamic-Internet----Modem ( Config DYNDNS user password host )-----Interconnection Palo Alto----Interface External Firewall Palo Alto--- DNATs on Palo Alto to your local resources and devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With that scheme, point everything to the Modem, to the Dynamica public Ip, then either use DMZ to forward all external traffic to the Palo Alto external IP or The Ip and certain Ports, then just do the DNATs you require on the Palo Alto and also a Source Nat, so that your devices can go out to the Internet through the Palo Alto and then they go out with an IP of the range of your LAN of the Modem and already, it is not complex at all, just make sure to configure DYNDNS in the modem, then point to the external IP of the Palo Alto and then in the Palo Alto configure the Destination Nats that you require, and that's it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 07:31:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snat-to-a-fqdn/m-p/520475#M107858</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2022-11-07T07:31:48Z</dc:date>
    </item>
  </channel>
</rss>

