<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Advanced Routing - NAT for overlapping networks between 2 logical routers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/advanced-routing-nat-for-overlapping-networks-between-2-logical/m-p/573619#M115322</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a Palo VM with advanced routing enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 2 customers with overlapping networks (172.16.0.0/24). Those networks must be accessible by the same servers (in connected network 10.1.1.0/24).&lt;BR /&gt;Customer1 network is routed via a static route to another router, Customer2 network is behind a IPSec VPN configured on the Palo VM.&lt;/P&gt;
&lt;P&gt;We can't ask any customer to add NAT rules on their side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first solution that came in our mind is to use destination NAT in order to hide the 2nd customer network with another one (10.2.2.0/24) on our side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What we tried to do is to configure a 2nd logical router (LR2) for customer 2, configure the IPSec tunnel interface there it, add Customer2 network 172.16.0.0/24 route via tunnel1 and to route 10.1.1.0/24 back to main logical router (LR1). On LR1 we have a route for the translated Customer2 network (10.2.2.0/24) via LR2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To access Customer2 network from servers we would use 10.2.2.0/24 network and translate it to 172.16.0.0/24 when it leaves LR2 via VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It doesn't work because the NAT rule is applied before the routing decision is made because the destination is translated to 172.16.0.0/24 before trafic being handle by LR2 and so is routed to Customer1 instead of Customer2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any idea how we can get around these limitations while still keeping traffic on the same firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Emilien RICHARD&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo.jpg" style="width: 880px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56670iA6F10D8076191128/image-dimensions/880x452/is-moderation-mode/true?v=v2" width="880" height="452" role="button" title="palo.jpg" alt="palo.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jan 2024 11:08:11 GMT</pubDate>
    <dc:creator>EmilienRichard</dc:creator>
    <dc:date>2024-01-19T11:08:11Z</dc:date>
    <item>
      <title>Advanced Routing - NAT for overlapping networks between 2 logical routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advanced-routing-nat-for-overlapping-networks-between-2-logical/m-p/573619#M115322</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a Palo VM with advanced routing enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 2 customers with overlapping networks (172.16.0.0/24). Those networks must be accessible by the same servers (in connected network 10.1.1.0/24).&lt;BR /&gt;Customer1 network is routed via a static route to another router, Customer2 network is behind a IPSec VPN configured on the Palo VM.&lt;/P&gt;
&lt;P&gt;We can't ask any customer to add NAT rules on their side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first solution that came in our mind is to use destination NAT in order to hide the 2nd customer network with another one (10.2.2.0/24) on our side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What we tried to do is to configure a 2nd logical router (LR2) for customer 2, configure the IPSec tunnel interface there it, add Customer2 network 172.16.0.0/24 route via tunnel1 and to route 10.1.1.0/24 back to main logical router (LR1). On LR1 we have a route for the translated Customer2 network (10.2.2.0/24) via LR2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To access Customer2 network from servers we would use 10.2.2.0/24 network and translate it to 172.16.0.0/24 when it leaves LR2 via VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It doesn't work because the NAT rule is applied before the routing decision is made because the destination is translated to 172.16.0.0/24 before trafic being handle by LR2 and so is routed to Customer1 instead of Customer2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any idea how we can get around these limitations while still keeping traffic on the same firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Emilien RICHARD&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo.jpg" style="width: 880px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56670iA6F10D8076191128/image-dimensions/880x452/is-moderation-mode/true?v=v2" width="880" height="452" role="button" title="palo.jpg" alt="palo.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 11:08:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advanced-routing-nat-for-overlapping-networks-between-2-logical/m-p/573619#M115322</guid>
      <dc:creator>EmilienRichard</dc:creator>
      <dc:date>2024-01-19T11:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Routing - NAT for overlapping networks between 2 logical routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advanced-routing-nat-for-overlapping-networks-between-2-logical/m-p/573715#M115339</link>
      <description>&lt;P&gt;Well forwarding look happens first and than the NAT lookup probably an issue with the route.&lt;BR /&gt;&lt;BR /&gt;In the slowpath stage of the life of packet first forwarding look happen than nat look for the destination nat.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 21:47:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advanced-routing-nat-for-overlapping-networks-between-2-logical/m-p/573715#M115339</guid>
      <dc:creator>msyeedrafiqi</dc:creator>
      <dc:date>2024-01-19T21:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Routing - NAT for overlapping networks between 2 logical routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advanced-routing-nat-for-overlapping-networks-between-2-logical/m-p/573784#M115351</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, there is a first route lookup then destination NAT rule applies but then another route lookup is done with the translated address. That’s what poses a problem to us. We are looking for another way to do this kind of configuration, have you other ideas ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;BR /&gt;see : &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_6364.jpeg" style="width: 998px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56727iBDD43CAA4EB5D82B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="IMG_6364.jpeg" alt="IMG_6364.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2024 12:58:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advanced-routing-nat-for-overlapping-networks-between-2-logical/m-p/573784#M115351</guid>
      <dc:creator>EmilienRichard</dc:creator>
      <dc:date>2024-01-20T12:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Routing - NAT for overlapping networks between 2 logical routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advanced-routing-nat-for-overlapping-networks-between-2-logical/m-p/574181#M115414</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Hopefully I understood the question. Check out this article on overlapping subnets.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSGCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSGCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 22:28:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advanced-routing-nat-for-overlapping-networks-between-2-logical/m-p/574181#M115414</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-01-23T22:28:31Z</dc:date>
    </item>
  </channel>
</rss>

