<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clarification Needed on Multiple Static NAT Rules with the Same Public IP Address in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-needed-on-multiple-static-nat-rules-with-the-same/m-p/1240922#M125439</link>
    <description>&lt;P data-start="0" data-end="13"&gt;Hey Tammam, &lt;BR /&gt;&lt;BR /&gt;That’s a really good question. What you’re seeing comes down to how the firewall treats session mappings. With dynamic NAT using a single public IP, the firewall assigns that address temporarily for the first session, and since the pool only contains one IP, other internal devices can’t reuse it until the mapping is released. &lt;BR /&gt;&lt;BR /&gt;With multiple static NAT rules, each PBX has its own translation rule even if they all use the same public IP. The firewall keeps separate session entries for each rule, so they don’t conflict. &lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/ngfw/networking/nat/dynamic-ip-and-port-nat-oversubscription" target="_self"&gt;https://docs.paloaltonetworks.com/ngfw/networking/nat/dynamic-ip-and-port-nat-oversubscription &lt;/A&gt;&lt;BR /&gt;&lt;A href="https://pingmynetwork.com/network/ccna-200-301/dynamic-nat" target="_self"&gt;https://pingmynetwork.com/network/ccna-200-301/dynamic-nat&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Oct 2025 23:01:23 GMT</pubDate>
    <dc:creator>Elwin3</dc:creator>
    <dc:date>2025-10-29T23:01:23Z</dc:date>
    <item>
      <title>Clarification Needed on Multiple Static NAT Rules with the Same Public IP Address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-needed-on-multiple-static-nat-rules-with-the-same/m-p/601423#M119553</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;I’m working with a customer who had previously configured a dynamic IP source NAT rule with only one address in the pool. This setup worked as expected for just one PBX since after the first session, the public IP would be in use, limiting further connections.&lt;/P&gt;
&lt;P&gt;However, the customer has now changed the configuration to use multiple static NAT rules, all using the same public IP but for different PBXs. Surprisingly, this is working, allowing multiple sessions to be translated to the same public IP via different NAT rules.&lt;/P&gt;
&lt;P&gt;What we’re trying to understand is why there’s a difference in behavior between the two scenarios:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;A single NAT rule with dynamic IP source translation using only one public IP in the pool.&lt;/LI&gt;
&lt;LI&gt;Multiple static NAT rules, all using the same public IP in the translated address.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Any insights into why these two configurations provide different results would be greatly appreciated!&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 08:29:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-needed-on-multiple-static-nat-rules-with-the-same/m-p/601423#M119553</guid>
      <dc:creator>TammamA</dc:creator>
      <dc:date>2024-10-16T08:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on Multiple Static NAT Rules with the Same Public IP Address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-needed-on-multiple-static-nat-rules-with-the-same/m-p/1240922#M125439</link>
      <description>&lt;P data-start="0" data-end="13"&gt;Hey Tammam, &lt;BR /&gt;&lt;BR /&gt;That’s a really good question. What you’re seeing comes down to how the firewall treats session mappings. With dynamic NAT using a single public IP, the firewall assigns that address temporarily for the first session, and since the pool only contains one IP, other internal devices can’t reuse it until the mapping is released. &lt;BR /&gt;&lt;BR /&gt;With multiple static NAT rules, each PBX has its own translation rule even if they all use the same public IP. The firewall keeps separate session entries for each rule, so they don’t conflict. &lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/ngfw/networking/nat/dynamic-ip-and-port-nat-oversubscription" target="_self"&gt;https://docs.paloaltonetworks.com/ngfw/networking/nat/dynamic-ip-and-port-nat-oversubscription &lt;/A&gt;&lt;BR /&gt;&lt;A href="https://pingmynetwork.com/network/ccna-200-301/dynamic-nat" target="_self"&gt;https://pingmynetwork.com/network/ccna-200-301/dynamic-nat&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2025 23:01:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-needed-on-multiple-static-nat-rules-with-the-same/m-p/1240922#M125439</guid>
      <dc:creator>Elwin3</dc:creator>
      <dc:date>2025-10-29T23:01:23Z</dc:date>
    </item>
  </channel>
</rss>

