<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Securing inbound traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/securing-inbound-traffic/m-p/28305#M20682</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds sensible - thanks Hulk.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 24 May 2014 00:35:46 GMT</pubDate>
    <dc:creator>svanrooyen</dc:creator>
    <dc:date>2014-05-24T00:35:46Z</dc:date>
    <item>
      <title>Securing inbound traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/securing-inbound-traffic/m-p/28303#M20680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully a fairly straight forward beginner question.&amp;nbsp; If I'm wanting to securely set up a basic inbound rule to direct traffic to a web service in our DMZ (from a single external source address), is it best to specify the source address in the NAT or Security policy - or both?&amp;nbsp; I'm trying to figure out the pro's and con's for both scenarios.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2014 22:40:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/securing-inbound-traffic/m-p/28303#M20680</guid>
      <dc:creator>svanrooyen</dc:creator>
      <dc:date>2014-05-23T22:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Securing inbound traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/securing-inbound-traffic/m-p/28304#M20681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the packet flow in PAN firewall, It will evaluate the NAT policy first and then, according to the translated address &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;NAT'd), it will search for an appropriate security policy. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest you to specify the source address in your NAT configuration, just to secure your webserver. Even if, you will not specify the source address on your NAT policy, the traffic will still be validated by security-policy lookup.&amp;nbsp; So, you must specify the source address into your security policy. Otherwise, anyone can initiate a traffic to the public IP (server's public IP address hosted in PAN firewall) and utilize it's CPU cycles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PacketProcessing-PAN.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13663_PacketProcessing-PAN.PNG" style="height: 419px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2014 23:03:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/securing-inbound-traffic/m-p/28304#M20681</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-23T23:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Securing inbound traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/securing-inbound-traffic/m-p/28305#M20682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds sensible - thanks Hulk.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 May 2014 00:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/securing-inbound-traffic/m-p/28305#M20682</guid>
      <dc:creator>svanrooyen</dc:creator>
      <dc:date>2014-05-24T00:35:46Z</dc:date>
    </item>
  </channel>
</rss>

