<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Understanding Static NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/understanding-static-nat/m-p/544824#M111473</link>
    <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;After further checking i see the same IP is being NATted to the different internal IP behind the LAN interface.&lt;/P&gt;
&lt;P&gt;That NAT is on TOP of the NAT rule base which could be the reason for traffic going to LAN interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much, i am bit confident now about the NATs in Palo after your confirmation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Issue is not resolved, i have requested customer to provide me the unused IP in the same subnet and awaiting response. Will let the trail updated.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jun 2023 14:57:47 GMT</pubDate>
    <dc:creator>Sanjay_Ramaiah</dc:creator>
    <dc:date>2023-06-05T14:57:47Z</dc:date>
    <item>
      <title>Understanding Static NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/understanding-static-nat/m-p/544789#M111467</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;When it comes to Static NAT it will be one to one NAT in vendors like Checkpoint and Cisco ASA. I am bit confused with the NAT configuration in Palo Alto. Went through config guide and examples of NAT as well but still confused.&lt;/P&gt;
&lt;P&gt;We have a scenario as below.&lt;/P&gt;
&lt;P&gt;We have 3 zones - WAN, LAN and DMZ.&lt;/P&gt;
&lt;P&gt;Users want to reach DMZ interface from WAN and vice versa.&lt;/P&gt;
&lt;P&gt;IP: 10.10.10.10 shd be translated to 1.1.1.2&lt;/P&gt;
&lt;P&gt;WAN Int: 1.1.1.1/29&lt;/P&gt;
&lt;P&gt;So ACL is configured as below:&lt;/P&gt;
&lt;P&gt;WAN to DMZ Zones port 443 is allowed.&lt;/P&gt;
&lt;P&gt;Src Int: WAN&lt;/P&gt;
&lt;P&gt;Src: Any&lt;/P&gt;
&lt;P&gt;Dst Int: DMZ&lt;/P&gt;
&lt;P&gt;Dst: 1.1.1.2&lt;/P&gt;
&lt;P&gt;Port: 443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Src Int: DMZ&lt;/P&gt;
&lt;P&gt;Src: 10.10.10.10&lt;/P&gt;
&lt;P&gt;Dst Int: WAN&lt;/P&gt;
&lt;P&gt;Dst: Any&lt;/P&gt;
&lt;P&gt;Port: 443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT:&lt;/P&gt;
&lt;P&gt;Src Zone: DMZ&lt;/P&gt;
&lt;P&gt;Dst Zone: WAN&lt;/P&gt;
&lt;P&gt;Dst Int: WAN&lt;/P&gt;
&lt;P&gt;Src Add: 10.10.10.10&lt;/P&gt;
&lt;P&gt;Dst Add:Any&lt;/P&gt;
&lt;P&gt;Src Trans: Static IP(1.1.1.2)Bi-directional&lt;/P&gt;
&lt;P&gt;Dst Trans:none&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Src Zone:WAN&lt;/P&gt;
&lt;P&gt;Dst Zone: DMZ&lt;/P&gt;
&lt;P&gt;Dst Int:DMZ&lt;/P&gt;
&lt;P&gt;Src Add:Any&lt;/P&gt;
&lt;P&gt;Dst Add:1.1.1.2&lt;/P&gt;
&lt;P&gt;Src Trans:none&lt;/P&gt;
&lt;P&gt;Dst Trans:dst-translation(10.10.10.10)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anything wrong with this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Though 1.1.1.2 is directly connected to WAN. Traffic from outside to 1.1.1.2 to is going to LAN interface instead of DMZ.&lt;/P&gt;
&lt;P&gt;I am concerned with my NAT understanding in Palo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestions on this would really help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 12:40:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/understanding-static-nat/m-p/544789#M111467</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-06-05T12:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Static NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/understanding-static-nat/m-p/544812#M111470</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That looks good.&amp;nbsp; The 2nd NAT entry is not needed because you configured the 1st one as bidirectional.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you give me the IP address/mask on the DMZ and LAN interfaces?&amp;nbsp; I am curious why the traffic is going to the LAN interface also.&amp;nbsp; Do you have other NAT rules &lt;EM&gt;above&lt;/EM&gt; the ones you listed?&amp;nbsp; I wonder if the traffic is hitting another rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 13:24:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/understanding-static-nat/m-p/544812#M111470</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-05T13:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Static NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/understanding-static-nat/m-p/544824#M111473</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;After further checking i see the same IP is being NATted to the different internal IP behind the LAN interface.&lt;/P&gt;
&lt;P&gt;That NAT is on TOP of the NAT rule base which could be the reason for traffic going to LAN interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much, i am bit confident now about the NATs in Palo after your confirmation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Issue is not resolved, i have requested customer to provide me the unused IP in the same subnet and awaiting response. Will let the trail updated.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 14:57:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/understanding-static-nat/m-p/544824#M111473</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-06-05T14:57:47Z</dc:date>
    </item>
  </channel>
</rss>

