<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Routing IP address range through firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19704#M14381</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As somewhat of a newby to PAN, I need to ask how do I go about passing an internal public IP range outbound through the firewall and NOT natting it.&amp;nbsp; This certain range of addresses will only connect to one other public IP address (different, external network) but the other address needs to be able to see these internal IP 's for what they are and not be natted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp; Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Mar 2011 15:47:36 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2011-03-24T15:47:36Z</dc:date>
    <item>
      <title>Routing IP address range through firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19704#M14381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As somewhat of a newby to PAN, I need to ask how do I go about passing an internal public IP range outbound through the firewall and NOT natting it.&amp;nbsp; This certain range of addresses will only connect to one other public IP address (different, external network) but the other address needs to be able to see these internal IP 's for what they are and not be natted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp; Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 15:47:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19704#M14381</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-03-24T15:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Routing IP address range through firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19705#M14382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can exempt certain IP's or subnets from NAT by keeping the Source and Destination Translation fields as "none"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="no-nat.jpg" class="jive-image-thumbnail jive-image" onclick="" src="https://live.paloaltonetworks.com/legacyfs/online/2312_no-nat.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 16:10:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19705#M14382</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-03-24T16:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Routing IP address range through firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19706#M14383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, this sounds like what I need to do.&amp;nbsp; If I set the source address to that of my internal range and the destination address to that of my target server, then the "no-natting' should only occur between those two sets of addresses, right?&amp;nbsp; Any extra Security policy rules needed( (other than what I already have in place)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 17:00:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19706#M14383</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-03-24T17:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Routing IP address range through firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19707#M14384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You got it.&amp;nbsp; You shouldn't need any other policy entries beyond what you would normally have in your Security Policy to allow the two segments to communicate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 17:07:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19707#M14384</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-03-24T17:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Routing IP address range through firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19708#M14385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Should that new NO NAT rule be placed above the normal outbound PAT rule everyone else on the network is using?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 21:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19708#M14385</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-03-24T21:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Routing IP address range through firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19709#M14386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Absolutely - all policy rules are evaluated top down and terminate on match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 21:32:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19709#M14386</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-03-24T21:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Routing IP address range through firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19710#M14387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;mwaters31 wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As somewhat of a newby to PAN, I need to ask how do I go about passing an internal public IP range outbound through the firewall and NOT natting it.&amp;nbsp; This certain range of addresses will only connect to one other public IP address (different, external network) but the other address needs to be able to see these internal IP 's for what they are and not be natted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp; Mike&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are your "internal" addresses RFC1918, and your external "live" Internet addresses? If so, I don't see how you're going to get your "inside" addresses routed by your external provider - ISP edge routers should be configured, by default, to drop anything from or two an RFC 1918 address range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enquiring mind wants to know. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your "internal" adresses are live, routable addresses then my question is probably invalid - also similarly invalid if your "external" link is some form of point-to-point link which only uses RFC1918 addressing in the path.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 23:18:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19710#M14387</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-03-24T23:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Routing IP address range through firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19711#M14388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The internal addresses of which I speak are in fact, live public addresses.&amp;nbsp; These are a small network that is part of a VPN server in which the server hands out addresses in this range to remote(Internet) clients that request them.&amp;nbsp; These addresses are then used to connect to the target IP address I mentioned earlier.&lt;/P&gt;&lt;P&gt;We were having some issues where when two or more vpn clients were connected, each one would lose its connection every 30 seconds, then regain it again.&amp;nbsp; Another agency (we are a city) had experienced the same issue and they resolved it by removing the natting their firewall was doing for their vpn clients.&lt;/P&gt;&lt;P&gt;Funny thing is, after I inserted the new "no nat" rule, I still wasn't seeing any traffic matching the rule in the Traffic logs.&amp;nbsp; The client "problem" had seemed to go away as well.&amp;nbsp; Success I thought.&amp;nbsp; Then I thought I would disable the new no nat rule to see if I could make the problem occur again.&amp;nbsp; Well, the problem didn't occur again and the clients kept operating normally.&amp;nbsp; So now I don't know if the new rule did anything or not.&amp;nbsp; Weird.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 16:01:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-ip-address-range-through-firewall/m-p/19711#M14388</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-03-25T16:01:46Z</dc:date>
    </item>
  </channel>
</rss>

