<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: to NAT pool or not in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17679#M12874</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Marsan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best practice is using NAT with Many to One, and as long as you use threat prevention to protect your incoming/outgoing traffic that will help as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any other questions please do let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Al&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Aug 2010 22:05:54 GMT</pubDate>
    <dc:creator>acamacho</dc:creator>
    <dc:date>2010-08-02T22:05:54Z</dc:date>
    <item>
      <title>to NAT pool or not</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17678#M12873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We have a brand new 2050 that is going to be used to support a school district with about 5000 students.... so we expect, eventually,&amp;nbsp; to have about 5000 to 6000 hosts going out to the internet. And we have access to a full class C public block.&lt;/P&gt;&lt;P&gt;The question that I have is: should we set this PA2050 to use a NAT pool or would setting it as "one-to-many" (where I would use only one public IP number for all my outgoing traffic) will be enough.&lt;/P&gt;&lt;P&gt;I would think that a pool makes more sense since it would eliminate the risk of having large amounts of traffic coming from the same IP number and therefore been tagged as spam.... but why would that matter if there would be 64K session&amp;nbsp; coming from the same IP&amp;nbsp; (Dynamic IP/Pool) before the next available IP gets used? Any feedback will be appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Aug 2010 21:36:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17678#M12873</guid>
      <dc:creator>marsan</dc:creator>
      <dc:date>2010-08-02T21:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: to NAT pool or not</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17679#M12874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Marsan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best practice is using NAT with Many to One, and as long as you use threat prevention to protect your incoming/outgoing traffic that will help as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any other questions please do let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Al&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Aug 2010 22:05:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17679#M12874</guid>
      <dc:creator>acamacho</dc:creator>
      <dc:date>2010-08-02T22:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: to NAT pool or not</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17680#M12875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add to that, the PA-2050 supports oversubscription of ports when using dynamic IP and port network address translation.&amp;nbsp; If your traffic is going to diverse destinations, the source port may be used twice.&amp;nbsp; So in your situation, you can support over 120,000 sessions on a single public IP.&amp;nbsp; This has the obvious advantage that you can support more sessions than would be supported by the number of IPs/ports you have in your NAT pool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;User A connects to Google.com&lt;/P&gt;&lt;P&gt;User B connects to Yahoo.com&lt;/P&gt;&lt;P&gt;Since the traffic is destined to different locations, the source port may be used for both (in the case that all of your ports are occupied by NAT traffic).&amp;nbsp; So the first flow, User A &amp;gt; Google.com, may be from public IP 1.1.1.1 and port 23001 and the second flow, User B &amp;gt; Yahoo.com, may also be from public IP 1.1.1.1 and port 23001.&amp;nbsp; The firewall can properly route the traffic to the correct host because it has a mapping between the destination and the original source address and port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick Campagna&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 14:53:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17680#M12875</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2010-08-10T14:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: to NAT pool or not</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17681#M12876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello ncampagna,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have helpful assistance by your comment.&lt;/P&gt;&lt;P&gt;Thanks a million.&lt;/P&gt;&lt;P&gt;I have more question.&lt;/P&gt;&lt;P&gt;What available number of same source port does FW have at different destination address???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 May 2013 04:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17681#M12876</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-05-27T04:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: to NAT pool or not</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17682#M12877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;An Nyeonghaseyo&lt;/P&gt;&lt;P&gt;Ga jang nim&lt;/P&gt;&lt;P&gt;Even though connect different dst address It will be used Source port about 64K&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wish You recommend me Like 乃&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 May 2013 12:00:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17682#M12877</guid>
      <dc:creator>SilverTiger</dc:creator>
      <dc:date>2013-05-27T12:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: to NAT pool or not</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17683#M12878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Cheon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find the total number on each platform's specsheet. For example, the PA-5060 can reuse each available source port up to 8 times (this is called &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;DIPP oversubscription on the specsheet). Since the available port range is roughly 1k-64k, it can use 63k source ports, with each creating up to 8 sessions if they're destined to different hosts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 13:24:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17683#M12878</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2013-05-28T13:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: to NAT pool or not</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17684#M12879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;while it set Many to one Public IP Address(PAT)&lt;BR /&gt;When &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Trust&lt;/STRONG&gt;&lt;/SPAN&gt; Private IP Address(192.168.0.1 - 192.168.255.254) try to connect &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Untrust&lt;/STRONG&gt;&lt;/SPAN&gt; same dst ip address or diffrent dst ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eventually &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Trust&lt;/STRONG&gt;&lt;/SPAN&gt; Private IP Address area have to use sharing source port within(64K).&lt;/P&gt;&lt;P&gt;is it right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 15:07:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17684#M12879</guid>
      <dc:creator>SilverTiger</dc:creator>
      <dc:date>2013-05-28T15:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: to NAT pool or not</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17685#M12880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, it will be one port per private IP (whatever the destination same or not).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 15:11:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-nat-pool-or-not/m-p/17685#M12880</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-05-28T15:11:33Z</dc:date>
    </item>
  </channel>
</rss>

