<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Source NAT confusion in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20125#M14647</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to provide for some 1-to-1 NAT on our PAN, which I thought we be an easy task.&amp;nbsp; However, my configuration insist on using the interface IP address for outbound connections.&amp;nbsp; Here is my setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Untrusted Network Interface IP: x.x.x.10/29&lt;/P&gt;&lt;P&gt;Trusted Network Interface IP: y.y.y.4/16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mail Server Public IP: x.x.x.12/32&lt;/P&gt;&lt;P&gt;Mail Server Private IP: y.y.y.50/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security_Policy_1&lt;/P&gt;&lt;P&gt;source zone: trusted&lt;/P&gt;&lt;P&gt;source address: y.y.y.50/16&lt;/P&gt;&lt;P&gt;destination zone: untrusted&lt;/P&gt;&lt;P&gt;destination address: any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT_Policy_1&lt;/P&gt;&lt;P&gt;Orginal Packet Source Zone: trusted&lt;/P&gt;&lt;P&gt;Original Packet Destination Zone: untrusted&lt;/P&gt;&lt;P&gt;Original Packet Source Address: x.x.x.12/32&lt;/P&gt;&lt;P&gt;Translated Packet: Static IP&lt;/P&gt;&lt;P&gt;Translated Address: y.y.y.50.32&lt;/P&gt;&lt;P&gt;Bi-Directional: yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Viewed from the mail server, it uses the interface IP to communicate, rather than the desired mail server's IP.&amp;nbsp; Where am I going wrong here?&amp;nbsp; Thank you&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Apr 2012 21:54:27 GMT</pubDate>
    <dc:creator>cdpadmin</dc:creator>
    <dc:date>2012-04-09T21:54:27Z</dc:date>
    <item>
      <title>Source NAT confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20125#M14647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to provide for some 1-to-1 NAT on our PAN, which I thought we be an easy task.&amp;nbsp; However, my configuration insist on using the interface IP address for outbound connections.&amp;nbsp; Here is my setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Untrusted Network Interface IP: x.x.x.10/29&lt;/P&gt;&lt;P&gt;Trusted Network Interface IP: y.y.y.4/16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mail Server Public IP: x.x.x.12/32&lt;/P&gt;&lt;P&gt;Mail Server Private IP: y.y.y.50/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security_Policy_1&lt;/P&gt;&lt;P&gt;source zone: trusted&lt;/P&gt;&lt;P&gt;source address: y.y.y.50/16&lt;/P&gt;&lt;P&gt;destination zone: untrusted&lt;/P&gt;&lt;P&gt;destination address: any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT_Policy_1&lt;/P&gt;&lt;P&gt;Orginal Packet Source Zone: trusted&lt;/P&gt;&lt;P&gt;Original Packet Destination Zone: untrusted&lt;/P&gt;&lt;P&gt;Original Packet Source Address: x.x.x.12/32&lt;/P&gt;&lt;P&gt;Translated Packet: Static IP&lt;/P&gt;&lt;P&gt;Translated Address: y.y.y.50.32&lt;/P&gt;&lt;P&gt;Bi-Directional: yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Viewed from the mail server, it uses the interface IP to communicate, rather than the desired mail server's IP.&amp;nbsp; Where am I going wrong here?&amp;nbsp; Thank you&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2012 21:54:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20125#M14647</guid>
      <dc:creator>cdpadmin</dc:creator>
      <dc:date>2012-04-09T21:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Source NAT confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20126#M14648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Checkout if:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1517" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can be of any help (specially example3 DMZ server outbound to Internet)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If im not mistaken the security rule is applied before SNAT happens which means you should use the real ip of the server and not the SNATed ip (compared to DNAT who happens before security rules are checked which means that security rules must act on the DNATed ip).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2012 22:56:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20126#M14648</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-04-09T22:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: Source NAT confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20127#M14649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To map the Mail Server Private IP: y.y.y.50/32 to the Mail Server Public IP: x.x.x.12/32, you bi-directional NAT configurations should look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT_Policy_1&lt;/P&gt;&lt;P&gt;Orginal Packet Source Zone: trusted&lt;/P&gt;&lt;P&gt;Original Packet Destination Zone: untrusted&lt;/P&gt;&lt;P&gt;Original Packet Source Address: &lt;EM&gt;&lt;STRONG&gt;y.y.y.50/32&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Translated Packet: Static IP&lt;/P&gt;&lt;P&gt;Translated Address: &lt;EM&gt;&lt;STRONG&gt;x.x.x.12/32&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Bi-Directional: yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Changes higlighed in &lt;STRONG&gt;&lt;EM&gt;BOLD.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also make sure that your more specific NAT entries (statics, bi-directionals) are at the top of the NAT policies and you more generic outbound NAT policies are at the bottom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ahsan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2012 23:32:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20127#M14649</guid>
      <dc:creator>akhan</dc:creator>
      <dc:date>2012-04-09T23:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: Source NAT confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20128#M14650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That was very helpful and allowed the server to web-browse using the correct IP address.&lt;BR /&gt;That same server is not available from the Internet.&amp;nbsp; I created an inbound security rule&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Mail Server Public IP: x.x.x.12/32&lt;/P&gt;&lt;P&gt;Mail Server Private IP: y.y.y.50/32 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security_Policy_2&lt;/P&gt;&lt;P&gt;source zone: untrusted&lt;/P&gt;&lt;P&gt;source address: any&lt;/P&gt;&lt;P&gt;destination zone: trusted&lt;/P&gt;&lt;P&gt;destination address: x.x.x.12/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security_Policy_2&lt;/P&gt;&lt;P&gt;source zone: untrusted&lt;/P&gt;&lt;P&gt;source address: any&lt;/P&gt;&lt;P&gt;destination zone: trusted&lt;/P&gt;&lt;P&gt;destination address: y.y.y.50/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Neither is getting me there.&amp;nbsp; &lt;BR /&gt;Thank you,&lt;BR /&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2012 00:50:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20128#M14650</guid>
      <dc:creator>cdpadmin</dc:creator>
      <dc:date>2012-04-11T00:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Source NAT confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20129#M14651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What does your traffic log tell you?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2012 06:13:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20129#M14651</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-04-11T06:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Source NAT confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20130#M14652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With some expert advise, I was able to complete this task.&amp;nbsp; Essentially, don't use the bi-directional translation option and use two distinct rules, one for inbound and one for outbound.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2012 21:25:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-confusion/m-p/20130#M14652</guid>
      <dc:creator>cdpadmin</dc:creator>
      <dc:date>2012-04-12T21:25:36Z</dc:date>
    </item>
  </channel>
</rss>

