<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MS-RDP NAT Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15221#M11175</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh, I see.&amp;nbsp; That makes a bit more sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Oct 2012 18:27:26 GMT</pubDate>
    <dc:creator>PurchasingMgr</dc:creator>
    <dc:date>2012-10-23T18:27:26Z</dc:date>
    <item>
      <title>MS-RDP NAT Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15217#M11171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to create a static destination NAT to enable RDP access on port 3389 for one of my internal servers, but no matter what I try, it just doesn't seem to work.&amp;nbsp; I've read through several KB articles as well as &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;https://live.paloaltonetworks.com/docs/DOC-1517&lt;/A&gt; and I've set everything up as it seems it should be, yet no NAT session is ever created. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My policies:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;NAT:&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;Policy 1:&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Original Packet:&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Source Zone:&amp;nbsp; untrust&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Destination Zone: untrust&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Destination Interface:&amp;nbsp; eth 1/1 (interface ip is 1.2.3.170/29)&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Service: Any&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Source Address:&amp;nbsp; Any&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Destination Address:&amp;nbsp; 1.2.3.172&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Translated Packet:&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Source Address Translation:&amp;nbsp; None&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Destination Address Translation:&lt;/P&gt;&lt;P style="padding-left: 150px;"&gt;Translated Address:&amp;nbsp; 172.16.200.11&lt;/P&gt;&lt;P style="padding-left: 150px;"&gt;Translated Port:&amp;nbsp; &amp;lt;blank&amp;gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;Policy 2:&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Original Packet:&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Source Zone:&amp;nbsp; trust&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Destination Zone:&amp;nbsp; untrust&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Destination Interface:&amp;nbsp; any&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Service:&amp;nbsp; any&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Source Address:&amp;nbsp; 172.16.200.11&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Destination Address:&amp;nbsp; any&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Translated Packet:&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Source Address Translation:&lt;/P&gt;&lt;P style="padding-left: 150px;"&gt;Translation Type:&amp;nbsp; Static IP&lt;/P&gt;&lt;P style="padding-left: 150px;"&gt;Translated Address:&amp;nbsp; 1.2.3.172&lt;/P&gt;&lt;P style="padding-left: 150px;"&gt;Bi-directional:&amp;nbsp; no (can't even find documentation on what this is, but I know it's supposed to be "no")&lt;/P&gt;&lt;P style="padding-left: 120px;"&gt;Destination Address Translation:&amp;nbsp; None&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;Policy 3:&amp;nbsp; Dynamic NAT policy that works properly.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Security:&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;Rule 1:&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Source Zone: untrust&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Source Address:&amp;nbsp; any&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;User: any&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Destination Zone:&amp;nbsp; trust&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Destination Address:&amp;nbsp; 172.16.200.11&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Application:&amp;nbsp; Remote Desktop (Application group with ms-rdp and t.120, though I've also tried with "Any")&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Service:&amp;nbsp; Any&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Action:&amp;nbsp; Allow&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;Log:&amp;nbsp; both start and end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The outbound NAT (Policy 2) portion works perfectly, and my internal server's source address is properly translated to the external address specified.&amp;nbsp; The Inbound NAT, however, does not work at all.&amp;nbsp; I don't see any security flows in the logs or anything else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know I'm probably missing something simple, I just can't seem to figure out what that is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any assistance in why this doesn't seem to be working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 17:15:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15217#M11171</guid>
      <dc:creator>PurchasingMgr</dc:creator>
      <dc:date>2012-10-23T17:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: MS-RDP NAT Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15218#M11172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Utilize the public ip address of the server (&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Destination Address:&amp;nbsp; 172.16.200.11&lt;/SPAN&gt;) in your security policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 17:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15218#M11172</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2012-10-23T17:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: MS-RDP NAT Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15219#M11173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a little illogical, but it seemed to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's my understanding that security rules are executed after the NAT rule (hence why your destination zone is "trust").&amp;nbsp; Why would the destination address be the external address if it's supposed to have already been translated?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 17:23:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15219#M11173</guid>
      <dc:creator>PurchasingMgr</dc:creator>
      <dc:date>2012-10-23T17:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: MS-RDP NAT Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15220#M11174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Took time for me to get this down as well but essentially, 'The addresses in the security policy refer to the IP address in the original packet i.e. the pre translated address. However the destination zone is the zone where the end host is physically connected."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 17:46:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15220#M11174</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2012-10-23T17:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: MS-RDP NAT Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15221#M11175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh, I see.&amp;nbsp; That makes a bit more sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 18:27:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-rdp-nat-issue/m-p/15221#M11175</guid>
      <dc:creator>PurchasingMgr</dc:creator>
      <dc:date>2012-10-23T18:27:26Z</dc:date>
    </item>
  </channel>
</rss>

