<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: STATIC NAT NOT WORKING in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/static-nat-not-working/m-p/1231717#M124564</link>
    <description>&lt;P&gt;you can't effectively nat for an IP subnet that is one hop away from the palo interface&lt;/P&gt;
&lt;P&gt;outbound NAT will work, the palo will source nat outgoing packets, the next hop router will (probably, unless this router supports anti-spoofing) route the packet to the final destination&lt;/P&gt;
&lt;P&gt;so far all will be good, but the reply packet will remain inside the local broadcast domain (the /24 subnet on the far end). the router will not know to forward that packet to 172.16.1.1 unless you set up some sort of proxy arp on the router&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can source nat behind 172.16.1.1 but not 172.16.100.x since that is one hop away&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tl;dr you're performing an old-school spoofing attack&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jun 2025 09:52:14 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2025-06-13T09:52:14Z</dc:date>
    <item>
      <title>STATIC NAT NOT WORKING</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-nat-not-working/m-p/1231547#M124548</link>
      <description>&lt;P&gt;Please consider below topology in which PC-1 - 3 are connected to Cisco Switch and having a gateway 192.168.1.1 configure on firewall. Firewall rule is any any and all the PC can ping the IT PC with actual IP. Now I want to deal with the scenario where all the PC-1 to 3 need to be statically translated to the IP in IT range which is 172.16.100.100 for PC-1 , 101 for PC-2 and 102 for PC-3 respectively but the scenario is not working. I would like to know how can we achieve this topolgy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;192.168.1.10 -- NAT TO -- 172.16.100.100&lt;/P&gt;
&lt;P&gt;192.168.1.11 -- NAT TO -- 172.16.100.101&lt;/P&gt;
&lt;P&gt;192.168.1.12 -- NAT TO -- 172.16.100.102&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried doing static NAT as per below and it is working but I dont want to do that&lt;/P&gt;
&lt;P&gt;192.168.1.10 -- NAT TO --172.16.1.3&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I missing something like proxy arp.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Him143u_1-1749663293591.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68003iEEAF81C63D17293C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Him143u_1-1749663293591.png" alt="Him143u_1-1749663293591.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 18:50:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-nat-not-working/m-p/1231547#M124548</guid>
      <dc:creator>Him143u</dc:creator>
      <dc:date>2025-06-11T18:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT NOT WORKING</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-nat-not-working/m-p/1231717#M124564</link>
      <description>&lt;P&gt;you can't effectively nat for an IP subnet that is one hop away from the palo interface&lt;/P&gt;
&lt;P&gt;outbound NAT will work, the palo will source nat outgoing packets, the next hop router will (probably, unless this router supports anti-spoofing) route the packet to the final destination&lt;/P&gt;
&lt;P&gt;so far all will be good, but the reply packet will remain inside the local broadcast domain (the /24 subnet on the far end). the router will not know to forward that packet to 172.16.1.1 unless you set up some sort of proxy arp on the router&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can source nat behind 172.16.1.1 but not 172.16.100.x since that is one hop away&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tl;dr you're performing an old-school spoofing attack&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 09:52:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-nat-not-working/m-p/1231717#M124564</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-06-13T09:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT NOT WORKING</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-nat-not-working/m-p/1231733#M124568</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would keep it simple and just use security policies to allow/deny traffic. No need to nat between subnets.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 18:40:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-nat-not-working/m-p/1231733#M124568</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-06-13T18:40:40Z</dc:date>
    </item>
  </channel>
</rss>

