<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNAT FW Palo Alto - Double NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530767#M109503</link>
    <description>&lt;P&gt;Did you understand what benefit customer would gain if this setup would work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Feb 2023 00:51:42 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-02-11T00:51:42Z</dc:date>
    <item>
      <title>DNAT FW Palo Alto - Double NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530766#M109502</link>
      <description>&lt;P&gt;DNAT Support - FW Palo Alto - Double NAT&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Hello Lice Community good afternoon, first of all, thanks for the support and collaboration always.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;I have received a very strange request, I have tried to configure it by trying many ways and nothing.&lt;/P&gt;
&lt;P class=""&gt;What does a client/costumer want:&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Dnat with double Nat ie.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Internet ======= Palo Alto Public IP direct to FW ===== DNAT to IP in DMZ range (Ip within the range, but a fictitious IP, that is, DMZ has a range of&lt;SPAN&gt;&amp;nbsp;&lt;A class="" href="https://192.168.5.0/24" target="_blank" rel="noopener nofollow ugc"&gt;192.168.5.0/24&lt;SPAN&gt;&amp;nbsp;and will be used the IP&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;A class="" href="https://192.168.5.100/" target="_blank" rel="noopener nofollow ugc"&gt;192.168.5.100)-----then DNAT again to the IP&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;A class="" href="https://10.10.10.100/" target="_blank" rel="noopener nofollow ugc"&gt;10.10.10.100&lt;SPAN&gt;&amp;nbsp;( Zone Inside ).&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;Now if I do it directly to the IP&lt;SPAN&gt;&amp;nbsp;&lt;A class="" href="https://10.10.10.100/" target="_blank" rel="noopener nofollow ugc"&gt;10.10.10.100&lt;SPAN&gt;&amp;nbsp;the DNAT works fine. I have done other NAT DNAT source NAT, Source NAT with IP range not directly connected to the FW and everything OK.&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;But when I do that double DNAT, it doesn't work, I've tried putting a route like /32 to the ip&lt;SPAN&gt;&amp;nbsp;&lt;A class="" href="https://192.168.3.100/32" target="_blank" rel="noopener nofollow ugc"&gt;192.168.3.100/32&lt;SPAN&gt;&amp;nbsp;and to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;A class="" href="https://10.10.10.100/32" target="_blank" rel="noopener nofollow ugc"&gt;10.10.10.100/32. Place a secondary IP in the DMZ Interface/Zone.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;The DNAT or NAT itself I have tried anyway.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Source any, destination DMZ&lt;SPAN&gt;&amp;nbsp;&lt;A class="" href="https://192.168.5.100/" target="_blank" rel="noopener nofollow ugc"&gt;192.168.5.100&lt;SPAN&gt;&amp;nbsp;DNAT at&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;A class="" href="https://10.10.10.100/" target="_blank" rel="noopener nofollow ugc"&gt;10.10.10.100.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Source any, destination Inside&lt;SPAN&gt;&amp;nbsp;&lt;A class="" href="https://10.10.10.100/" target="_blank" rel="noopener nofollow ugc"&gt;10.10.10.100&lt;SPAN&gt;&amp;nbsp;DNAT&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;A class="" href="https://192.168.5.200/" target="_blank" rel="noopener nofollow ugc"&gt;192.168.5.200.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;And all the possible variants and nothing, no hit.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Security policies also all possible variants.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;That double nat is feasible, for me it doesn't make much sense to the truth, but technically it is feasible, because no matter how much I move it, nothing happens.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Thank you, I remain attentive to any advice, collaboration, etc.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2023 00:40:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530766#M109502</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-02-11T00:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT FW Palo Alto - Double NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530767#M109503</link>
      <description>&lt;P&gt;Did you understand what benefit customer would gain if this setup would work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2023 00:51:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530767#M109503</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-02-11T00:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT FW Palo Alto - Double NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530768#M109504</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot for your answer-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What the client wants, stubbornly... I have already spoken with them and told them to review it, but they were also given the full explanation that it does not make much sense or does not have added value to do something like this. But he insists on confirming the feasibility and whether Palo Alto supports it.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;I clarify the detail:&lt;BR /&gt;&lt;SPAN&gt;Internet-----Public-Ip----IP of the range of the Interface/DMZ Zone 192.168.5.100 and that in turn when the request arrives at IP 192.168.5.100 the FW does another DNAT when hitting 5.100 DNAT towards the final IP 10.10.10.100 in the Inside interface/zone.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Summary: Internet---IpPublic---PaloAlto----DNAT to DMZ&amp;nbsp;&lt;A class="" href="https://192.168.5.100/" target="_blank" rel="noopener nofollow ugc"&gt;192.168.5.100&amp;nbsp;----SAME-FW-PaloAlto---Dnat 5.100 to&amp;nbsp;&lt;/A&gt;&lt;A class="" href="https://10.10.10.100/" target="_blank" rel="noopener nofollow ugc"&gt;10.10.10.100&amp;nbsp;( same PA Inside Zone ).&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Internet IP---from FW---DNAT to IP dummy/loopback/ipsecondary IP of the DMZ-Zone interface ----( Not a Host IP: IP dummy/loopback/ipsecondary Interface DMZ, IP:&lt;A class="" href="https://192.168.5.100/" target="_blank" rel="noopener nofollow ugc"&gt;192.168.5.100&amp;nbsp;) ----And when it hits the&amp;nbsp;&lt;/A&gt;&lt;A class="" href="https://192.168.5.100/" target="_blank" rel="noopener nofollow ugc"&gt;192.168.5.100&amp;nbsp;of the same Fw-PA----DNAT go to IP&amp;nbsp;&lt;/A&gt;&lt;A class="" href="https://10.10.10.100/" target="_blank" rel="noopener nofollow ugc"&gt;10.10.10.100&amp;nbsp;the final server in the Inside/LAN zone.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For me a madness that does not make any sense, but I must justify well why not and why it cannot be done, it is not feasible or it is not convenient.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2023 02:27:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530768#M109504</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-02-11T02:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT FW Palo Alto - Double NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530769#M109505</link>
      <description>&lt;P&gt;It is easy to do.&lt;/P&gt;
&lt;P&gt;Customer buys another Palo.&lt;/P&gt;
&lt;P&gt;Set up external firewall that will DNAT to &lt;SPAN&gt;192.168.5.100 &lt;/SPAN&gt;and internal firewall that will perform second DNAT and voila - 2x NAT is achieved &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On more serious note for Palo to send traffic to&amp;nbsp;&lt;SPAN&gt;192.168.5.100 something needs to reply to arp on that IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If Palo has&amp;nbsp;192.168.5.100 configured on itself it will never send out arp requests for this IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can set up packet capture filter and use "show counter global filter delta yes packet-filter yes" and see why packet is dropped.&lt;/P&gt;
&lt;P&gt;If this is not enough then take flow basic logs.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2023 02:47:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530769#M109505</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-02-11T02:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: DNAT FW Palo Alto - Double NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530771#M109506</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp; good evening:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, hehe, it makes sense, because that double DNAT in the same firewall, understanding that the "one session/packets" Firewall cannot go through two DNATs in the same network device and/or firewall, it doesn't make much sense, going to the theoretical basis of networking and NAT.&lt;/P&gt;
&lt;P&gt;Yes, it would be a second firewall, a load balancer and/or a reverse proxy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2023 04:33:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnat-fw-palo-alto-double-nat/m-p/530771#M109506</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-02-11T04:33:37Z</dc:date>
    </item>
  </channel>
</rss>

