<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Desktop for Administration ONLY in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/remote-desktop-for-administration-only/m-p/24192#M17641</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I figured out my problem. In the NAT settings the Source AND Destination Zones need to be set to l3-untrusted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps someone else out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Dec 2010 20:19:46 GMT</pubDate>
    <dc:creator>numberall</dc:creator>
    <dc:date>2010-12-15T20:19:46Z</dc:date>
    <item>
      <title>Remote Desktop for Administration ONLY</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-desktop-for-administration-only/m-p/24191#M17640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, I'm stuck. I'm trying to allow external acces for Remote Desktop, but only for Administering our Server not for Virtual Apps. I created a NAT Rule as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name: Inbound Remote Desktop&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Zone: l3-untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination Zone: l3-trust&lt;/P&gt;&lt;P&gt;&amp;nbsp; Destination Interface: Any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Address: Any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service: TCP_Port5000&amp;nbsp;&amp;nbsp; (Outside port is 5000)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Translation: None&lt;/P&gt;&lt;P&gt;Destination Translation: 10.0.0.50 and Port 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And a Security Rule as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name: RemoteDesktop In to Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Zone: l3-untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination Zone: l3-trust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Address: any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source User: any&lt;/P&gt;&lt;P&gt;Destination Address: 222.222.222.222&amp;nbsp; (example outside address)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application: ms-rdp, t.120&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Action: Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Profile: Block virus, spyware&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I missing, any help is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 20:04:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-desktop-for-administration-only/m-p/24191#M17640</guid>
      <dc:creator>numberall</dc:creator>
      <dc:date>2010-12-15T20:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Desktop for Administration ONLY</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-desktop-for-administration-only/m-p/24192#M17641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I figured out my problem. In the NAT settings the Source AND Destination Zones need to be set to l3-untrusted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps someone else out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 20:19:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-desktop-for-administration-only/m-p/24192#M17641</guid>
      <dc:creator>numberall</dc:creator>
      <dc:date>2010-12-15T20:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Desktop for Administration ONLY</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-desktop-for-administration-only/m-p/24193#M17642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad you figured it out.&amp;nbsp; Another way to do this in PAN-OS 3.1 and later is to create an outbound source-nat for the server/service and configure the source-nat as 'bidirectional'.&amp;nbsp; This will create the secondary inbound destination-nat in the background.&amp;nbsp; It will essentially be a hidden rule that looks like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;source-zone:&amp;nbsp; any&lt;/P&gt;&lt;P&gt;dst-zone: source-zone of the outbound bidirectional nat rule&lt;/P&gt;&lt;P&gt;destination-nat: source-nat ip of the outbound bidirectional nat rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This guarantees the same IP for inbound and outbound initiated traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 22:46:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-desktop-for-administration-only/m-p/24193#M17642</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-12-15T22:46:54Z</dc:date>
    </item>
  </channel>
</rss>

