<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT and Security Policies, PBF Failover and Symmetric Return - Dual ISP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-and-security-policies-pbf-failover-and-symmetric-return-dual/m-p/23159#M16885</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) You have to create a second NAT rule which's interface will be different&lt;/P&gt;&lt;P&gt;2)You can use 1 rule regarding to ALL server IP addresses inside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 31 May 2013 08:46:15 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-05-31T08:46:15Z</dc:date>
    <item>
      <title>NAT and Security Policies, PBF Failover and Symmetric Return - Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-and-security-policies-pbf-failover-and-symmetric-return-dual/m-p/23158#M16884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is two parts:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) I configured Destination NAT rules and corresponding Security Policies to allow inbound access to servers on private LAN.&amp;nbsp; These all utilize the Primary ISP public IP address.&amp;nbsp; If I want these internal servers accessible over the Secondary ISP (as we already have configured PBF failover to the secondary ISP should the primary go down), do I then have to create duplicate NAT rules and Security Policies for each, replacing the Primary ISP IP with the Secondary ISP IP?&amp;nbsp; Or, is there a way to just do NATs and Security Policies to handle both ISPs in a single rule and corresponding policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) With the PBF Failover, I've read about symmetric return being needed for Dual ISPs.&amp;nbsp; The document "Symmetic Return.docx" gives an example, but it's Dual ISPs being NATed and Security Policy'ed to one internal server.&amp;nbsp; If I have rules for several internal servers, does that mean I have to create several PBF rules enforcing symmetric return for each private server, or can I just create one PBF rule enabling symmetric return for the ISP the traffic came through on, period?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 03:32:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-and-security-policies-pbf-failover-and-symmetric-return-dual/m-p/23158#M16884</guid>
      <dc:creator>uscit</dc:creator>
      <dc:date>2013-04-16T03:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAT and Security Policies, PBF Failover and Symmetric Return - Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-and-security-policies-pbf-failover-and-symmetric-return-dual/m-p/23159#M16885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) You have to create a second NAT rule which's interface will be different&lt;/P&gt;&lt;P&gt;2)You can use 1 rule regarding to ALL server IP addresses inside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 08:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-and-security-policies-pbf-failover-and-symmetric-return-dual/m-p/23159#M16885</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-05-31T08:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAT and Security Policies, PBF Failover and Symmetric Return - Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-and-security-policies-pbf-failover-and-symmetric-return-dual/m-p/23160#M16886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you implement something like gslb?&lt;/P&gt;&lt;P&gt;if it done, the client will be redirected to the internal server via&amp;nbsp; the public ip either from&amp;nbsp; your first provider or the second (it depend the load balancing mecanisme, it could be a just a failover)&lt;/P&gt;&lt;P&gt;and you need 1 destinations NAT rule as destination orginal packet base on the 2 public ip and transfert to the same server private ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;G&amp;nbsp; &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 14:15:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-and-security-policies-pbf-failover-and-symmetric-return-dual/m-p/23160#M16886</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-05-31T14:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: NAT and Security Policies, PBF Failover and Symmetric Return - Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-and-security-policies-pbf-failover-and-symmetric-return-dual/m-p/73644#M41485</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i have slightly different scenario here-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) we have 2 ISP (ISP1 - eth1/1 &amp;amp; ISP2- eth1/8)&lt;/P&gt;&lt;P&gt;2) 3 zones - Trust, Wi-FI, Untrust (ISP1) &amp;amp; ISPB (ISP2)&lt;/P&gt;&lt;P&gt;3) Trust &amp;amp; Wi-Fi zones access internet via Untrust.&lt;/P&gt;&lt;P&gt;4) Destination NAT configured (published web apps ) on Untrust (ISP1 IP)&lt;/P&gt;&lt;P&gt;4) Trust &amp;amp; Wi-Fi machines are allowed to access published web apps using internet IP addresses.(U-turn NAT)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Desired setup (working)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) internet access from Zone - Trust via ISP1 (untrust)&lt;/P&gt;&lt;P&gt;2) internet access from Zone - Wi-Fi via ISPB (ISP2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trouble facing:&lt;/P&gt;&lt;P&gt;1) Wi-Fi Zone users can't access published service (Destination NAT) from ISP-B (ex: webmail/vpn..etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[in a TCP 3-way handshake, syn is reaching to interal server but, syn-ack is not reaching the client]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me to resolve the issue&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 06:44:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-and-security-policies-pbf-failover-and-symmetric-return-dual/m-p/73644#M41485</guid>
      <dc:creator>janu.rafi</dc:creator>
      <dc:date>2016-02-26T06:44:30Z</dc:date>
    </item>
  </channel>
</rss>

