<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT mapping public to private IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-mapping-public-to-private-ip/m-p/583908#M116676</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been updating our NAT policies within our PA-3220 to specify traffic translation mapping from our public addresses to private addresses. After committing the changes the traffic has only been routing to the catch all NAT rule at the bottom of our NAT policies. I am concerned that I did not configure everything correctly after following Palo's guide and would like any suggestions to correct the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The current NAT configurations look like this (image attached below):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Name: Squid Proxy | Source: Untrusted | Destination : Trusted | Destination Interface: e1/19 | Source Address: Any | Destination: (Public IP) | Service: Any | Source Translation: dynamic-ip-and-port, e1/19 | Destination Translation: 10.20.1.249&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be appreciated. Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2024 15:16:20 GMT</pubDate>
    <dc:creator>BenjaminRaimondi</dc:creator>
    <dc:date>2024-04-16T15:16:20Z</dc:date>
    <item>
      <title>NAT mapping public to private IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-mapping-public-to-private-ip/m-p/583908#M116676</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been updating our NAT policies within our PA-3220 to specify traffic translation mapping from our public addresses to private addresses. After committing the changes the traffic has only been routing to the catch all NAT rule at the bottom of our NAT policies. I am concerned that I did not configure everything correctly after following Palo's guide and would like any suggestions to correct the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The current NAT configurations look like this (image attached below):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Name: Squid Proxy | Source: Untrusted | Destination : Trusted | Destination Interface: e1/19 | Source Address: Any | Destination: (Public IP) | Service: Any | Source Translation: dynamic-ip-and-port, e1/19 | Destination Translation: 10.20.1.249&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be appreciated. Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 15:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-mapping-public-to-private-ip/m-p/583908#M116676</guid>
      <dc:creator>BenjaminRaimondi</dc:creator>
      <dc:date>2024-04-16T15:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: NAT mapping public to private IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-mapping-public-to-private-ip/m-p/583913#M116678</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/793632343"&gt;@BenjaminRaimondi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please change your destination zone to untrusted as well. In your security policy, the destination zone will be the true source zone. Here is a very helpful article written by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;on NATs. &lt;A href="https://live.paloaltonetworks.com/t5/community-blogs/i-m-gonna-make-him-a-nat-rule-he-can-t-refuse/ba-p/148940" target="_blank"&gt;https://live.paloaltonetworks.com/t5/community-blogs/i-m-gonna-make-him-a-nat-rule-he-can-t-refuse/ba-p/148940&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 16:24:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-mapping-public-to-private-ip/m-p/583913#M116678</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-04-16T16:24:38Z</dc:date>
    </item>
  </channel>
</rss>

