<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forward from multiple WAN to one host LAN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17594#M12829</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to define 2 inbound NAT rules on the PA firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rule1 dest=1.1.1.1 translate to destIP=3.3.3.3&lt;/P&gt;&lt;P&gt;rule2 dest=2.2.2.2 translate to destIP=3.3.3.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The inbound NAT setting can be found here:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;https://live.paloaltonetworks.com/docs/DOC-1517&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You must also define security rule(s) to allow the traffic (i.e. the ms-rdp app) from the WAN to 3.3.3.3. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Jan 2012 22:50:02 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2012-01-11T22:50:02Z</dc:date>
    <item>
      <title>forward from multiple WAN to one host LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17593#M12828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV dir="ltr" style="zoom:1"&gt;Hi,&lt;BR /&gt; I need a little help with PA configuration. I have two WAN links.&lt;BR /&gt; WAN1 - 1.1.1.1&lt;BR /&gt; WAN2 - 2.2.2.2&lt;BR /&gt; and a host on the network 3.3.3.3&lt;BR /&gt; 3.3.3.3 ip&amp;nbsp; is a terminal server. All computers go through WAN1 link. I need to configure the PA so I can login to the server via IP WAN1 and IP WAN2. I ask for directions if possible. Advance thank you very much.&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jan 2012 22:13:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17593#M12828</guid>
      <dc:creator>marcinpudysz</dc:creator>
      <dc:date>2012-01-11T22:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: forward from multiple WAN to one host LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17594#M12829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to define 2 inbound NAT rules on the PA firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rule1 dest=1.1.1.1 translate to destIP=3.3.3.3&lt;/P&gt;&lt;P&gt;rule2 dest=2.2.2.2 translate to destIP=3.3.3.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The inbound NAT setting can be found here:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;https://live.paloaltonetworks.com/docs/DOC-1517&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You must also define security rule(s) to allow the traffic (i.e. the ms-rdp app) from the WAN to 3.3.3.3. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jan 2012 22:50:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17594#M12829</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-01-11T22:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: forward from multiple WAN to one host LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17595#M12830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you for your reply.&lt;BR style="font-family: arial, sans-serif; font-size: 16px; text-align: -webkit-auto; background-color: #f5f5f5;" /&gt;That's what I did and it did not work.&lt;BR style="font-family: arial, sans-serif; font-size: 16px; text-align: -webkit-auto; background-color: #f5f5f5;" /&gt;It works only on a WAN link (1.1.1.1) which is set in the virtual router as the default route. I can not connect to a terminal server via WAN2 link (2.2.2.2). I think theproblem is in the configuration of virtual router. If I change the default route is WAN2can connect only through WAN2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2012 22:28:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17595#M12830</guid>
      <dc:creator>marcinpudysz</dc:creator>
      <dc:date>2012-01-12T22:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: forward from multiple WAN to one host LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17596#M12831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure to put both WAN links in the same zone.&amp;nbsp; Looks like you are seeing asymmetric routing with the return flows and the sessions are probably not matching up.&amp;nbsp; I'm not sure, but there may be other fancy ways of fixing this with Policy Based Forwarding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2012 23:41:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17596#M12831</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2012-01-12T23:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: forward from multiple WAN to one host LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17597#M12832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for your help. Everything works very well.&lt;BR style="font-family: arial, sans-serif; font-size: 16px; text-align: -webkit-auto; background-color: #f5f5f5;" /&gt;Both WAN interfaces must be in the same zone.&lt;BR style="font-family: arial, sans-serif; font-size: 16px; text-align: -webkit-auto; background-color: #f5f5f5;" /&gt;For virtual router I had to add two routes 0.0.0.0 / 0 with different metrics. Once again,thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jan 2012 00:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17597#M12832</guid>
      <dc:creator>marcinpudysz</dc:creator>
      <dc:date>2012-01-13T00:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: forward from multiple WAN to one host LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17598#M12833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I continue this discussion because we experimented exactly the same problem, and we applied the proposal configuration that we found in the previous post.&lt;/P&gt;&lt;P&gt;We have the two WAN interfaces in the same zone. We configured the two routes 0.0.0.0/0 with different metrics, but we don't solve the problem.&lt;/P&gt;&lt;P&gt;At the moment it's possible to access to the internal host only from one of the two WAN interfaces, not from the the other one.&lt;/P&gt;&lt;P&gt;Can anyone help me?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2012 07:39:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17598#M12833</guid>
      <dc:creator>s_dutto</dc:creator>
      <dc:date>2012-06-05T07:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: forward from multiple WAN to one host LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17599#M12834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have 2 public IP ranges, 1 IP range per ISP?&amp;nbsp; It may that ISP1 will not permit IP of ISP2, or vice versa.&amp;nbsp;&amp;nbsp; Traffic coming into ISP2 is be replied out ISP1 due the default route and ISP1 is dropping the traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2012 12:35:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17599#M12834</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-06-05T12:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: forward from multiple WAN to one host LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17600#M12835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;THE SITUATION YESTERDAY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;two different provider&lt;/P&gt;&lt;P&gt;ISP1 - 1.1.1.0/24&lt;/P&gt;&lt;P&gt;ISP2 - 2.2.2.0/24&lt;/P&gt;&lt;P&gt;INTERNAL HOST - 3.3.3.3/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT RULES&lt;/P&gt;&lt;P&gt;1.1.1.10 -&amp;gt; 3.3.3.3&lt;/P&gt;&lt;P&gt;2.2.2.10 -&amp;gt; 3.3.3.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ROUTES&lt;/P&gt;&lt;P&gt;0.0.0.0/0 -&amp;gt; 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I use 1.1.1.10 I can access the host, if I use 2.2.2.10 no. We look at the traffic in this second case. The packets enter the ISP2, reach the internal host 3.3.3.3 and go outside (using routing table) ISP1 so it doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THE SITUATION TODAY (after reading this discussion)&lt;/P&gt;&lt;P&gt;two different provider&lt;/P&gt;&lt;P&gt;ISP1 - 1.1.1.0/24&lt;/P&gt;&lt;P&gt;ISP2 - 2.2.2.0/24&lt;/P&gt;&lt;P&gt;INTERNAL HOST - 3.3.3.3/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT RULES&lt;/P&gt;&lt;P&gt;1.1.1.10 -&amp;gt; 3.3.3.3&lt;/P&gt;&lt;P&gt;2.2.2.10 -&amp;gt; 3.3.3.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ROUTES (as suggested in this post)&lt;/P&gt;&lt;P&gt;0.0.0.0/0 -&amp;gt; 1.1.1.1 (metric x)&lt;/P&gt;&lt;P&gt;0.0.0.0/0 -&amp;gt; 2.2.2.1 (metric y)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand how this solution can work. If I use 1.1.1.10 all is ok. If I use 2.2.2.10 the packet enter ISP2, reach the INTERNAL HOST 3.3.3.3 and go outside ISP1 (using the routing table).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any solution I can configure to use both ISP1 and ISP2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2012 12:58:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17600#M12835</guid>
      <dc:creator>s_dutto</dc:creator>
      <dc:date>2012-06-05T12:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: forward from multiple WAN to one host LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17601#M12836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's work fine. If you use pbf rules you must add new rule with destination address 3.3.3.3 and action no-pbf.&lt;/P&gt;&lt;P&gt;in some situations may arise asymetric routing. (i have that problem and this is solusion) &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2012 13:21:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17601#M12836</guid>
      <dc:creator>marcinpudysz</dc:creator>
      <dc:date>2012-06-05T13:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: forward from multiple WAN to one host LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17602#M12837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears your 2 ISPs will only permit their own IP range and not the other ISP's.&amp;nbsp; We need to ensure the return traffic goes out the same ISP. Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA1 default route 0.0.0.0/0 --&amp;gt; 1.1.1.1&lt;/P&gt;&lt;P&gt;PA2 default route 0.0.0.0/0 --&amp;gt; 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do not sync the virtual-router (VR) so each PA will keep its own def route.&amp;nbsp; This setting in under the HA configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the inbound NAT, you need to do BOTH src &amp;amp; dst NAT so the return packets will come back to the same PA.&amp;nbsp; Let's say the inside IP of PA1 is 3.3.3.1 and PA2 is 3.3.3.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT RULES on PA1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srcIP: any --&amp;gt; 3.3.3.1 and dstIP: 1.1.1.10 -&amp;gt; 3.3.3.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ensures the replies from 3.3.3.3 will go back to 3.3.3.1, PA1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT RULES on PA2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srcIP: any --&amp;gt; 3.3.3.2 and dstIP: 2.2.2.10 -&amp;gt; 3.3.3.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ensures the replies from 3.3.3.3 will go to 3.3.3.2, PA2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2012 19:20:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-from-multiple-wan-to-one-host-lan/m-p/17602#M12837</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-06-05T19:20:48Z</dc:date>
    </item>
  </channel>
</rss>

