<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Sanity Check in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-sanity-check/m-p/567445#M114612</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can I sanity check a NAT rule please. We have a small satellite office with a PA as the firewall. We only have /30 subnet so one IP for the router and one for the IP of the external NIC on the PA.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We need to have a connection for a service to a telephone system that comes from external to the telephone. So because of the IP limitation need to NAT behind the external interface.&amp;nbsp; I've created an internal object for the IP address of the telephone, an object for the external IP of the FW NIC and a NAT rule. The zones are just LAN and WAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The NAT rule is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Original Packet tab&lt;/P&gt;
&lt;P&gt;the Zone is Internal for the Source&lt;/P&gt;
&lt;P&gt;On the Destination Zone is the WAN&lt;/P&gt;
&lt;P&gt;Source address is the internal object IP address for the telephone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Translated Packet Tab&lt;/P&gt;
&lt;P&gt;Translation Type is Static IP in Source address Translation&lt;/P&gt;
&lt;P&gt;Translated address is the IP of the external NIC of the FW&lt;/P&gt;
&lt;P&gt;Bi-directional is ticked Yes.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;That should work and achieve what is required??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for any help, it is appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Nov 2023 20:53:02 GMT</pubDate>
    <dc:creator>newcollegedurham</dc:creator>
    <dc:date>2023-11-28T20:53:02Z</dc:date>
    <item>
      <title>NAT Sanity Check</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-sanity-check/m-p/567445#M114612</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can I sanity check a NAT rule please. We have a small satellite office with a PA as the firewall. We only have /30 subnet so one IP for the router and one for the IP of the external NIC on the PA.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We need to have a connection for a service to a telephone system that comes from external to the telephone. So because of the IP limitation need to NAT behind the external interface.&amp;nbsp; I've created an internal object for the IP address of the telephone, an object for the external IP of the FW NIC and a NAT rule. The zones are just LAN and WAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The NAT rule is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Original Packet tab&lt;/P&gt;
&lt;P&gt;the Zone is Internal for the Source&lt;/P&gt;
&lt;P&gt;On the Destination Zone is the WAN&lt;/P&gt;
&lt;P&gt;Source address is the internal object IP address for the telephone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Translated Packet Tab&lt;/P&gt;
&lt;P&gt;Translation Type is Static IP in Source address Translation&lt;/P&gt;
&lt;P&gt;Translated address is the IP of the external NIC of the FW&lt;/P&gt;
&lt;P&gt;Bi-directional is ticked Yes.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;That should work and achieve what is required??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for any help, it is appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 20:53:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-sanity-check/m-p/567445#M114612</guid>
      <dc:creator>newcollegedurham</dc:creator>
      <dc:date>2023-11-28T20:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Sanity Check</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-sanity-check/m-p/567511#M114618</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/116895"&gt;@newcollegedurham&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am guessing you have also "default" source hide-NAT rule at the bottom, which will translate all internal networks to internet, is that correct? If yes, I am not sure if using the same public IP for static NAT and for dynamic ip and port (DIPP) will not cause commit error. I could be wrong, but I am trying to imagine how FW will handle the port mapping for each session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Creating static source NAT with bi-directional will NAT will create destination NAT rule matching any destination port. I would suggest you to consider to create the inbound NAT rule manually instead of using the bi-directional feature.&lt;/P&gt;
&lt;P&gt;- First benefit it will be visible in the GUI, so it will be easier to be spot&lt;/P&gt;
&lt;P&gt;- Second benefit is that you can specify port or port range, which leaves you options to use the other available ports for future needs. This could be little tricky as you want to NAT telephone system, which will require some large port ranges.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 08:25:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-sanity-check/m-p/567511#M114618</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-11-29T08:25:26Z</dc:date>
    </item>
  </channel>
</rss>

