<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Meraki behind PA - Unfriedly NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa-unfriedly-nat/m-p/566487#M114482</link>
    <description>&lt;P&gt;Hello, thank you very much for the help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I knew the articles, but read them again and tried to build the NATs step by step.&lt;BR /&gt;No matter what NAT rule I build, it has 0 hits.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you tell me what the SNAT-DNAT rules have to look like in order for it to work?&lt;BR /&gt;Maybe mine is correct, but the problem lies somewhere else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My config:&lt;/STRONG&gt;&lt;BR /&gt;IP Meraki = 10.10.10.1&lt;BR /&gt;IP PA IF6.3321 = 10.10.10.2&lt;BR /&gt;IP PA IF1 = 195.300.299.298 (Public)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Zones:&lt;/STRONG&gt;&lt;BR /&gt;LAN: ethernet1/6.3321&lt;BR /&gt;WAN: ethernet1/1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My source NAT rule:&lt;/STRONG&gt;&lt;BR /&gt;Source Zone: LAN&lt;BR /&gt;Destination Zone: WAN&lt;BR /&gt;Destination Interface: IP PA IF1&lt;BR /&gt;Source Address: IP PA IF6.3321&lt;BR /&gt;Destination Address: ANY&lt;BR /&gt;Service: UDP_23543&lt;BR /&gt;Source Translation: Type: static-ip, Address: 195.300.299.298&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;My destination NAT rule:&lt;/STRONG&gt;&lt;BR /&gt;Source Zone: WAN&lt;BR /&gt;Destination Zone: WAN&lt;BR /&gt;Destination Interface: ANY&lt;BR /&gt;Source Address: ANY&lt;BR /&gt;Destination Address: 195.300.299.298&lt;BR /&gt;Service: UDP_23543&lt;BR /&gt;Destination Translation: Type: static-ip, Address: IP Meraki&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Both rules have no hits and the Meraki still says Unfriendly NAT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2023 13:49:41 GMT</pubDate>
    <dc:creator>Frank_Liebelt</dc:creator>
    <dc:date>2023-11-21T13:49:41Z</dc:date>
    <item>
      <title>Meraki behind PA - Unfriedly NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa-unfriedly-nat/m-p/565251#M114321</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;another person with the problem. I know, I know. Finding a solution to this problem is obviously not easy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem with a Meraki cluster behind a PA cluster.&lt;BR /&gt;The problem is the familiar “Unfriendly NAT”.&lt;BR /&gt;I just can't figure out how to configure the PA so that it works. Countless articles on the internet don't help either.&lt;BR /&gt;The last one I read was:&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa850-site-to-site-error-unfriendly-nat/m-p/259750#M73626" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa850-site-to-site-error-unfriendly-nat/m-p/259750#M73626&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The setup:&lt;BR /&gt;The two Merakis have the IPs 10.10.10.1 and 10.10.10.2. The virtual IP of the WAN1 port is 10.10.10.3. (/29)&lt;BR /&gt;On the PA, port 5 is configured with 10.10.10.4.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA's WAN is ethernet1/1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The NAT rule on the PA:&lt;BR /&gt;Source: LAN&lt;BR /&gt;Destination: WAN&lt;BR /&gt;Destination IF: ethernet1/1&lt;BR /&gt;Source Address: 10.10.10.4/29&lt;BR /&gt;Destination Address: Any&lt;BR /&gt;Service: Any&lt;BR /&gt;Source Translation:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Type: dynamic-ip-and-port&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Address Type: Interface Address&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Interface: ethernet1/1&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; IP Address: PA's Public IP&lt;BR /&gt;Destination Translation: none&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a big problem with two locations with the same setup.&lt;/P&gt;
&lt;P&gt;No Meraki SD-WAN VPN connections are established between these locations.&lt;BR /&gt;All other locations that only have a Meraki as a breakout can connect to the two locations without any problems.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Until recently we still had Sophos and it worked wonderfully. But dismantling the PA cannot be the solution &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2023 00:38:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa-unfriedly-nat/m-p/565251#M114321</guid>
      <dc:creator>Frank_Liebelt</dc:creator>
      <dc:date>2023-11-12T00:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki behind PA - Unfriedly NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa-unfriedly-nat/m-p/565252#M114322</link>
      <description>&lt;P&gt;Try to add DNAT for traffic coming from Internet to Meraki.&lt;/P&gt;
&lt;P&gt;Although bi-directional setting in NAT policy would do it for you I highly discourage to use it as it is not exactly the same as creating 2 rules (SNAT and DNAT) manually.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Settings#NAT_Traversal" target="_blank"&gt;https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Settings#NAT_Traversal&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2023 01:41:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa-unfriedly-nat/m-p/565252#M114322</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-12T01:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki behind PA - Unfriedly NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa-unfriedly-nat/m-p/566487#M114482</link>
      <description>&lt;P&gt;Hello, thank you very much for the help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I knew the articles, but read them again and tried to build the NATs step by step.&lt;BR /&gt;No matter what NAT rule I build, it has 0 hits.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you tell me what the SNAT-DNAT rules have to look like in order for it to work?&lt;BR /&gt;Maybe mine is correct, but the problem lies somewhere else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My config:&lt;/STRONG&gt;&lt;BR /&gt;IP Meraki = 10.10.10.1&lt;BR /&gt;IP PA IF6.3321 = 10.10.10.2&lt;BR /&gt;IP PA IF1 = 195.300.299.298 (Public)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Zones:&lt;/STRONG&gt;&lt;BR /&gt;LAN: ethernet1/6.3321&lt;BR /&gt;WAN: ethernet1/1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My source NAT rule:&lt;/STRONG&gt;&lt;BR /&gt;Source Zone: LAN&lt;BR /&gt;Destination Zone: WAN&lt;BR /&gt;Destination Interface: IP PA IF1&lt;BR /&gt;Source Address: IP PA IF6.3321&lt;BR /&gt;Destination Address: ANY&lt;BR /&gt;Service: UDP_23543&lt;BR /&gt;Source Translation: Type: static-ip, Address: 195.300.299.298&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;My destination NAT rule:&lt;/STRONG&gt;&lt;BR /&gt;Source Zone: WAN&lt;BR /&gt;Destination Zone: WAN&lt;BR /&gt;Destination Interface: ANY&lt;BR /&gt;Source Address: ANY&lt;BR /&gt;Destination Address: 195.300.299.298&lt;BR /&gt;Service: UDP_23543&lt;BR /&gt;Destination Translation: Type: static-ip, Address: IP Meraki&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Both rules have no hits and the Meraki still says Unfriendly NAT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 13:49:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa-unfriedly-nat/m-p/566487#M114482</guid>
      <dc:creator>Frank_Liebelt</dc:creator>
      <dc:date>2023-11-21T13:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki behind PA - Unfriedly NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa-unfriedly-nat/m-p/598332#M119016</link>
      <description>&lt;P&gt;Was there a solution to this short of dedicating a static address on the outside to the Meraki?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 16:11:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-behind-pa-unfriedly-nat/m-p/598332#M119016</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2024-09-19T16:11:50Z</dc:date>
    </item>
  </channel>
</rss>

