<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port forwarding through ipsec tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585950#M116944</link>
    <description>&lt;P&gt;Of course!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will also need to do a source NAT to a prefix on the public static IP FW so that the return traffic is routed back.&amp;nbsp; The easiest way to do it is put IP addresses on your tunnel interfaces (one on each side) and source NAT to the tunnel IP.&amp;nbsp; The prefix on the tunnels can be a /30 or even a /31.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Tue, 07 May 2024 01:18:50 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-05-07T01:18:50Z</dc:date>
    <item>
      <title>Port forwarding through ipsec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585938#M116940</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two Pa-440's.&amp;nbsp; One 440 has a public static ip and the other is just dhcp as of right now.&amp;nbsp; &amp;nbsp; &amp;nbsp;I do a site to site to site vpn working between them.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I setup an original port forward on the public&amp;nbsp; static ip device to a local host and it worked great.&amp;nbsp; &amp;nbsp;Now, I moved that host to a subnet on the public dhcp firewall.&amp;nbsp; &amp;nbsp;I tried switching the port forward to the new ip at the remote location across the tunnel interface,&amp;nbsp; but it never seems to work.&amp;nbsp; Is this possible to do?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bryan&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 22:37:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585938#M116940</guid>
      <dc:creator>btolkawfp</dc:creator>
      <dc:date>2024-05-06T22:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Port forwarding through ipsec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585940#M116941</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1009996901"&gt;@btolkawfp&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT over VPN is definitely possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Do you have a route pointing to the subnet on the public dhcp firewall to the tunnel interface?&lt;/LI&gt;
&lt;LI&gt;Did you change the destination zone of the NAT policy rule &lt;EM&gt;and &lt;/EM&gt;security policy rule to reflect the change?&lt;/LI&gt;
&lt;LI&gt;Do you see the failed traffic under Monitor &amp;gt; Logs &amp;gt; Traffic?&amp;nbsp; Many times the log will reveal why it isn't working.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 23:20:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585940#M116941</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-06T23:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Port forwarding through ipsec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585947#M116943</link>
      <description>&lt;P&gt;1.)&amp;nbsp; The site to site between firewalls is working&lt;/P&gt;
&lt;P&gt;2.)&amp;nbsp; the destination zone of the port forward is untrust and untrust&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.) no failed logs ..just says incomplete.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the issue is getting the client using the public ip and then natting that request through a vpn tunnel and then back to the original firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 00:48:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585947#M116943</guid>
      <dc:creator>btolkawfp</dc:creator>
      <dc:date>2024-05-07T00:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Port forwarding through ipsec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585950#M116944</link>
      <description>&lt;P&gt;Of course!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will also need to do a source NAT to a prefix on the public static IP FW so that the return traffic is routed back.&amp;nbsp; The easiest way to do it is put IP addresses on your tunnel interfaces (one on each side) and source NAT to the tunnel IP.&amp;nbsp; The prefix on the tunnels can be a /30 or even a /31.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 01:18:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585950#M116944</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-07T01:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Port forwarding through ipsec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585993#M116954</link>
      <description>&lt;P&gt;ok that makes more sense.. i am still having a hard time visualizing that source nat configuration.&amp;nbsp; Here is port forward rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="btolkawfp_0-1715092442228.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59561i95C480DAE59F0574/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="btolkawfp_0-1715092442228.png" alt="btolkawfp_0-1715092442228.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I added a tunnel interface of 10.10.10.9/30 to the public dhcp firewall and 10.10.10.10/30 to the static firewall&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 15:18:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/585993#M116954</guid>
      <dc:creator>btolkawfp</dc:creator>
      <dc:date>2024-05-07T15:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Port forwarding through ipsec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/586023#M116961</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1009996901"&gt;@btolkawfp&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can modify the same rule to NAT the source IP to 10.10.10.10.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 15:38:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/586023#M116961</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-07T15:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Port forwarding through ipsec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/586049#M116969</link>
      <description>&lt;P&gt;thanks got it work..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 17:28:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-forwarding-through-ipsec-tunnel/m-p/586049#M116969</guid>
      <dc:creator>btolkawfp</dc:creator>
      <dc:date>2024-05-07T17:28:05Z</dc:date>
    </item>
  </channel>
</rss>

