<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAT/NAT rule not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593028#M118024</link>
    <description>&lt;P&gt;Can anyone advised on this, like hitting my head against a brick wall atm&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2024 15:58:46 GMT</pubDate>
    <dc:creator>M.Allen</dc:creator>
    <dc:date>2024-07-25T15:58:46Z</dc:date>
    <item>
      <title>PAT/NAT rule not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593018#M118020</link>
      <description>&lt;P&gt;Hi I am looking to create a PAT for an internal server which will use the /30 public IP of the Palo outside interface and port&amp;nbsp;16385 to be reachable.&amp;nbsp;The below scenario:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;PAT/static NAT towards the private IP of O-IntercomSRV-01 (the intercom server) using UDP port 16385 from sources OG-Parking-Intercom-Dest source port 16385.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;O-IntercomSRV-01 -&amp;nbsp;192.168.1.9&lt;/P&gt;
&lt;P&gt;OG-Parking-Intercom-Dest -&amp;nbsp;O-Parking-Intercom-Dest-01 - O-Parking-Intercom-Dest-02 (public IPs)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this how I would set this up?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAllen_0-1721916847976.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61070i4863B6729BBEE866/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MAllen_0-1721916847976.png" alt="MAllen_0-1721916847976.png" /&gt;&lt;/span&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAllen_1-1721916864575.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61071i76CD166E96731153/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MAllen_1-1721916864575.png" alt="MAllen_1-1721916864575.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAllen_2-1721916898264.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61074i2BDE05F68283EDB4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MAllen_2-1721916898264.png" alt="MAllen_2-1721916898264.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAllen_3-1721916944923.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61073iFEA063C40727C167/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MAllen_3-1721916944923.png" alt="MAllen_3-1721916944923.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I am getting an error message when committing..&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAllen_4-1721917034857.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61075i2427910F86CE0588/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MAllen_4-1721917034857.png" alt="MAllen_4-1721917034857.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 14:17:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593018#M118020</guid>
      <dc:creator>M.Allen</dc:creator>
      <dc:date>2024-07-25T14:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: PAT/NAT rule not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593028#M118024</link>
      <description>&lt;P&gt;Can anyone advised on this, like hitting my head against a brick wall atm&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 15:58:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593028#M118024</guid>
      <dc:creator>M.Allen</dc:creator>
      <dc:date>2024-07-25T15:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: PAT/NAT rule not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593241#M118071</link>
      <description>&lt;P&gt;Still not able to get this working..&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2024 09:22:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593241#M118071</guid>
      <dc:creator>M.Allen</dc:creator>
      <dc:date>2024-07-28T09:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: PAT/NAT rule not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593262#M118072</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1252419965"&gt;@M.Allen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see this&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clt4CAC" target="_blank" rel="noopener"&gt;Commit NAT Error: Mismatch of destination address translation range"" (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004MfyCAE&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;Error message: “Mismatch of destination address translation ran... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 03:39:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593262#M118072</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2024-07-29T03:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: PAT/NAT rule not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593474#M118115</link>
      <description>&lt;P&gt;the object used in the pre-NAT destination probably has a /30 subnet?&amp;nbsp; and the post-nat destination is a /32, this is a faulty NAT operation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also, it looks like you're setting up an inbound rule: an inbound NAT (or PAT) rule should be untrust to untrust as the destination address (pre-nat) is on the untrust interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so your rule should read:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;original packet: from untrust to untrust, source parking-OG destination public-IP service 16385&lt;/P&gt;
&lt;P&gt;translated packet: static ip, destination 192.168.1.9&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 09:02:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pat-nat-rule-not-working/m-p/593474#M118115</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-07-30T09:02:43Z</dc:date>
    </item>
  </channel>
</rss>

