<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: reconfigure DNS and PAN3020 firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28275#M20654</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to my above NAT examples, here is our example of how to configure the U-Turn NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let us know if you have any questions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15928" alt="uturn.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15928_uturn.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Sep 2014 22:40:50 GMT</pubDate>
    <dc:creator>mmmccorkle</dc:creator>
    <dc:date>2014-09-30T22:40:50Z</dc:date>
    <item>
      <title>reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28270#M20649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently i two AD dns zones in on my DNS server (windows):&lt;/P&gt;&lt;P&gt;mycompanydom.com - internal domain&lt;/P&gt;&lt;P&gt;mycompanyplan.com - external domain where all our internet webservers and web applications live. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my A records in mycompanyplan.com point to internal non routable IPaddress for each internal server so the traffic does not go out the firewall and back in.&amp;nbsp; We also have 3 IPSEC VPN tunnels where the dns zone information is replicated to. My problem that i run into is if a tunnel goes down then my users in those sites cannot get to the services they need because their dns query is resolving to a non routable internal IP and trying to go down the tunnel vs resolving to the external IP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to remove that zone completely&amp;nbsp; from my DNS infrastructure and that way all dns queries to mycompanyplan.com resolve to the external IP's instead. My 3 satellite offices would route out their firewall to the external IP vs currently routing down the vpn tunnels.&amp;nbsp; Is there a way to configure the PAN3020's in my HQ where all of my inbound web services reside to see the traffic and have it loop back without having to go out the external interfaces only to come back in? Not sure if i am making sense while writing this, so if you need clarification please let me know.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe a another way to say this is, if a company has inbound web servers how is everyone setting up DNS and routing traffic when those web servers are in the same office but have need to be accessible externally? Is there a way to prevent that traffic from leaving the firewall only to come back in?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2014 21:33:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28270#M20649</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-30T21:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28271#M20650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/7065"&gt;EDSAadmin&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Sounds like you need to configure a U-Turn NAT Policy. You can access internal resources via a public IP address or public pointing A record. By using this link you will access the same A record that you would from the external and you will have access to the services. Use this link below and I have attached screenshots as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1678"&gt;How to Configure U-Turn NAT&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;U-TURN NAT POLICY&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15932" alt="U-TurnNATPolicy.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15932_U-TurnNATPolicy.png" style="width: 620px; height: 47px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SECURITY POLICY:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;your security policy will vary based on your needs&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15933" alt="U-Turn2ZoneSecPolicy.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15933_U-Turn2ZoneSecPolicy.png" style="width: 620px; height: 65px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2014 21:36:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28271#M20650</guid>
      <dc:creator>jperry1</dc:creator>
      <dc:date>2014-09-30T21:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28272#M20651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello EDS admin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on description U-Turn NAT will help in this scenario. But still few information is unclear.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1678"&gt;How to Configure U-Turn NAT&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;Following Two Sentences are contradictory:&lt;/STRONG&gt; Please clarify.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;mycompanyplan.com - external domain where all our internet webservers and web applications live.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;my A records in mycompanyplan.com point &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;to internal non routable IPaddress for each internal server so the traffic does not go out the firewall and back in&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Regards,&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2014 22:30:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28272#M20651</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-30T22:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28273#M20652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi EDSAdmin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use public IP address across the tunnel. If traffic flows through Tunnel than NAT it to Private IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If tunnel is down and its going through regular internet link than also server will be accessible through public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2014 22:33:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28273#M20652</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-30T22:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28274#M20653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Indeed, we will need a U-Turn NAT configuration here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition to the NAT documents provided above, here is a good illustration of how the Palo Alto appliance handles NAT and why the U-Turn NAT rules will have to be configured in a specific way that may not make sense at first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NAT processing.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15907_NAT processing.jpg" style="height: 710px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2014 22:37:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28274#M20653</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2014-09-30T22:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28275#M20654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to my above NAT examples, here is our example of how to configure the U-Turn NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let us know if you have any questions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15928" alt="uturn.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15928_uturn.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2014 22:40:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28275#M20654</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2014-09-30T22:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28276#M20655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/servlet/JiveServlet/downloadBody/1517-102-7-11647/Understanding_NAT-4.1-RevC.pdf" title="https://live.paloaltonetworks.com/servlet/JiveServlet/downloadBody/1517-102-7-11647/Understanding_NAT-4.1-RevC.pdf"&gt;https://live.paloaltonetworks.com/servlet/JiveServlet/downloadBody/1517-102-7-11647/Understanding_NAT-4.1-RevC.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Will help you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Oct 2014 06:13:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28276#M20655</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-10-01T06:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28277#M20656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in the two sentences that you mentioned to clarify. &lt;/P&gt;&lt;P&gt; the a records i am referring to that point to non routable IP addresses, what i meant was the A records in my windows DNS server. i have zone there that is called mycompanyplan.com. in that zone all of my webservers A records have internal non routable ips for each webserver so they do not go out the firewall. what i want to do is delete that zone and only have my A records that are configured on network solutions and then as&amp;nbsp; you guys have pointed out setup a u-turn rules. &lt;/P&gt;&lt;P&gt;Will i need a NAT and security rule for each web server, or can i do like jperry posted which from the way i am reading it allows one run to cover all my servers. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Oct 2014 03:40:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28277#M20656</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-10-02T03:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28278#M20657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;hshah wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hi EDSAdmin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can use public IP address across the tunnel. If traffic flows through Tunnel than NAT it to Private IP address.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If tunnel is down and its going through regular internet link than also server will be accessible through public IP.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Hardik Shah&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how would i set this up? would this be instead of the u-turn or in addition to adding the u-turn? what is the best practice/preferred method?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Oct 2014 03:43:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28278#M20657</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-10-02T03:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28279#M20658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/7065"&gt;EDSAadmin&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you will need a Uturn NAT and security rule for each server to allow this to one. Because with out the U-Turn NAT rule you will not be able to route to the A record on the Public IP address and without the Security Policy you will not be able to allow traffic to your server. If you already have a security policy for your server then you don't need an additional security policy. Let me know if you have further questions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also are you using Exchange Outlook anywhere? Is your internal domain name the same as you external domain name?&amp;nbsp; If so that could be interesting and U-turn NAT may be the best solution but let me know the details. If you are using Exchange 2010 I have deployed that in multiple scenarios as well is 2007 and below. Let me know when you can.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Oct 2014 05:45:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28279#M20658</guid>
      <dc:creator>jperry1</dc:creator>
      <dc:date>2014-10-02T05:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: reconfigure DNS and PAN3020 firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28280#M20659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello EDS Admin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is easiest implementation for IPsec hosts. BELIEVE ME. THINK OVER THIS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hi EDSAdmin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;You can use public IP address across the tunnel. If traffic flows through Tunnel than NAT it to Private IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;If tunnel is down and its going through regular internet link than also server will be accessible through public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Regards,&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Oct 2014 13:59:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconfigure-dns-and-pan3020-firewall/m-p/28280#M20659</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-02T13:59:04Z</dc:date>
    </item>
  </channel>
</rss>

