<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT'ing subnets - Larger to smaller? Will it work? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ing-subnets-larger-to-smaller-will-it-work/m-p/541118#M110942</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This will work as long as no communication traversing the tunnel expects a certain source port to function properly. If that isn't a requirement, you could set this to DIPP and it would work perfectly fine.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 May 2023 20:57:50 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-05-04T20:57:50Z</dc:date>
    <item>
      <title>NAT'ing subnets - Larger to smaller? Will it work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ing-subnets-larger-to-smaller-will-it-work/m-p/541043#M110931</link>
      <description>&lt;P&gt;I'm moving some rules from an ASA we will be decommissioning at another location to our local PA-5220 for an IPSEC tunnel that we are migrating. The existing rule set on our ASA is NAT'ing our /16 subnet onto a /24 which technically could be an issue but we have few users that use this tunnel so it isn't an issue and they could come from a number of places on our internal /16.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to do this with PAN-OS?&amp;nbsp; When I looked at this document:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllzCAC" target="_blank"&gt;Getting Started: Network Address Translation (NAT) - Knowledge Base - Palo Alto Networks&lt;/A&gt;&amp;nbsp;it had a caveat about being the same size subnets but it looks like that is only if using Dynamic IP and NOT dynamic IP and port.&amp;nbsp; I'm just uncertain at the moment if this tunnel requires the source ports to remain the same - I doubt it but its possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for any help or insight.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 11:59:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-ing-subnets-larger-to-smaller-will-it-work/m-p/541043#M110931</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-05-04T11:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT'ing subnets - Larger to smaller? Will it work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ing-subnets-larger-to-smaller-will-it-work/m-p/541118#M110942</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This will work as long as no communication traversing the tunnel expects a certain source port to function properly. If that isn't a requirement, you could set this to DIPP and it would work perfectly fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 20:57:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-ing-subnets-larger-to-smaller-will-it-work/m-p/541118#M110942</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-05-04T20:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAT'ing subnets - Larger to smaller? Will it work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-ing-subnets-larger-to-smaller-will-it-work/m-p/541119#M110943</link>
      <description>&lt;P&gt;That is great news! Thanks.&amp;nbsp; I doubt highly the source port matters at all but I'll probably take a closer look at the logs and see what shows up soon on the ASA.&amp;nbsp; I'm still in discovery mode on some of this but this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 20:59:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-ing-subnets-larger-to-smaller-will-it-work/m-p/541119#M110943</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-05-04T20:59:26Z</dc:date>
    </item>
  </channel>
</rss>

