<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble routing from Guest zone to Internal Server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576451#M115694</link>
    <description>&lt;P&gt;There is a separate destination NAT for external users. My source IP is from our 10.193.0.0 subnet (Guest) and guest interface ethernet 1/5.93.&amp;nbsp; The destination is listed as the public IP with a NAT IP displayed as the server's private IP.&amp;nbsp; So to me, it does appear correct.&amp;nbsp; We have other configurations for the Guest wifi to reach internal services, but those are handled by the load balancer in the DMZ, so we're not sure where the disconnect is occurring.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Feb 2024 14:04:22 GMT</pubDate>
    <dc:creator>cnorwich</dc:creator>
    <dc:date>2024-02-07T14:04:22Z</dc:date>
    <item>
      <title>Trouble routing from Guest zone to Internal Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576319#M115679</link>
      <description>&lt;P&gt;I'm not sure where to turn from here but my organization is trying to do a configuration we haven't set up before related to our student self-service system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To try and summarize the issue, we have a guest-wireless zone that we need to allow anybody access to another server that is internal on our production network.&amp;nbsp; Our system architect registered a public IP address to our ISP with a URL so what we're trying to do is allow guest-wifi to this public URL and then let it hit the internal server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is working externally from the organization.&amp;nbsp; There is a NAT setup to allow external traffic to reach the service via the public IP/URL, but trying to go from the Guest Zone to the server is giving problem.&amp;nbsp; I have had Palo support troubleshooting with me and they were not able to come up with a solution during our call, so I'm turning here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What some other Palo documentation and videos had us do was the following NAT and Security Policy:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT&lt;/P&gt;
&lt;P&gt;Source Zone: inside&lt;/P&gt;
&lt;P&gt;Dest. Zone: Outside&lt;/P&gt;
&lt;P&gt;Source Addr: Server Private IP&lt;/P&gt;
&lt;P&gt;Src. Translation: Server Public IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This worked for anything external but trying to recreate one for Guest doesn't seem to do anything&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Security Policy&lt;/P&gt;
&lt;P&gt;Source Zone: Guest&lt;/P&gt;
&lt;P&gt;Source Addr: Any&lt;/P&gt;
&lt;P&gt;Dest. Zone: inside&lt;/P&gt;
&lt;P&gt;Dest. Addr: server Public IP&lt;/P&gt;
&lt;P&gt;Ports: 80/443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Traffic Monitor for the above security policy shows allowed traffic with a result of Application: Incomplete.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am completely stumped and feel like we're making it a lot harder than it really is, so any guidance would be immensely helpful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 20:33:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576319#M115679</guid>
      <dc:creator>cnorwich</dc:creator>
      <dc:date>2024-02-06T20:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble routing from Guest zone to Internal Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576324#M115680</link>
      <description>&lt;P&gt;Is the guest zone hitting the public IP? Presumably your NAT rule is bi-directional then? Or do you have a separate NAT policy for inbound connections?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you look in the details of the session you see allowed, in both the source and destination boxs does the "NAT IP" part appear correct?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 21:01:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576324#M115680</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-02-06T21:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble routing from Guest zone to Internal Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576328#M115681</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Sounds like you need a U-Turn NAT.&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cln3CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cln3CAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also make sure you have security policies allowing the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 21:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576328#M115681</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-02-06T21:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble routing from Guest zone to Internal Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576451#M115694</link>
      <description>&lt;P&gt;There is a separate destination NAT for external users. My source IP is from our 10.193.0.0 subnet (Guest) and guest interface ethernet 1/5.93.&amp;nbsp; The destination is listed as the public IP with a NAT IP displayed as the server's private IP.&amp;nbsp; So to me, it does appear correct.&amp;nbsp; We have other configurations for the Guest wifi to reach internal services, but those are handled by the load balancer in the DMZ, so we're not sure where the disconnect is occurring.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 14:04:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576451#M115694</guid>
      <dc:creator>cnorwich</dc:creator>
      <dc:date>2024-02-07T14:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble routing from Guest zone to Internal Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576452#M115695</link>
      <description>&lt;P&gt;I did come across something regarding U-Turn NAT and I did try and use the above link for reference, as well as another online video of someone explaining it and it makes sense to me, but when trying to implement I'm still not able to reach that service.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":frowning_face:"&gt;☹️&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 14:06:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576452#M115695</guid>
      <dc:creator>cnorwich</dc:creator>
      <dc:date>2024-02-07T14:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble routing from Guest zone to Internal Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576457#M115698</link>
      <description>&lt;P&gt;After a little more looking into the NAT policy, I recognized the error I had.&amp;nbsp; U-Turn was the correct solution but it was the particular interface I was using on the source translation.&amp;nbsp; Correcting that on my end immediately got the service working.&amp;nbsp; Much thanks to all.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 14:28:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-from-guest-zone-to-internal-server/m-p/576457#M115698</guid>
      <dc:creator>cnorwich</dc:creator>
      <dc:date>2024-02-07T14:28:39Z</dc:date>
    </item>
  </channel>
</rss>

