<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem setting up a U-Turn NAT rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29662#M21671</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to confirm, I think your oscp.company.com resolves to the loopback address 10.99.99.1 in your diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, I think your rules need to have 10.99.99.1 as the destination address and then put 100.1.1.1 as the translated destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;keep the source translation as it is now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are basically doing a double nat on both source and destination to create the U-turn for your setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 21 Jun 2014 11:42:23 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2014-06-21T11:42:23Z</dc:date>
    <item>
      <title>Problem setting up a U-Turn NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29658#M21667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While trying to setup LSVPN on our HQ Palo Alto device, we ran into a U-Turn NAT issue. Let me first explain the setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14032" alt="U-Turn NAT Example.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14032_U-Turn NAT Example.png" style="height: 219px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We setup an OCSP responder using a loopback Interface on the PA firewall. The private IP address of that loopback interface is 10.99.99.1/32. The private IP is not being used outside the firewall. Instead, all "clients" in the External AND Trusted cloud connect to "ocsp.company.com" which resolves to 100.1.1.1 in both clouds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now access to "ocsp.company.com" from the External cloud is easy. That works well. However, so far we didn't manage to create a working U-Turn NAT rule for access from the Trusted cloud. Any ideas how this could be accomplished?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we tried so far (not successful):&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14051" alt="U-Turn NAT - rules.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14051_U-Turn NAT - rules.png" style="height: 75px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;(We couldn't easily visualize the fake IP address in the "Source Translation" section in the first rule. But we tried with 10.1.1.1/24 as Source Translation IP.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 12:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29658#M21667</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2014-06-20T12:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Problem setting up a U-Turn NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29659#M21668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you seen this example configuration on U Turn NAT walks through the process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1678"&gt;How to Configure U-Turn NAT&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 13:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29659#M21668</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-06-20T13:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Problem setting up a U-Turn NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29660#M21669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I've seen that. I also posted a comment on that post a while back &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do have other U-Turn NATs in place but none with a single-IP loopback interface...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 13:19:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29660#M21669</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2014-06-20T13:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Problem setting up a U-Turn NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29661#M21670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Oliver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you add the loopback interface to the external zone ? You would normally not need to do source nat as the ip is located in a different zone, but you will need to make sure the nat rule you create is above your generic "outbound" nat so you don't do hide-nat when accessing this loopback&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your nat rules should look like this more or less:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14052" alt="2014-06-20_16-31-35.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14052_2014-06-20_16-31-35.png" style="height: 43px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 14:32:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29661#M21670</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2014-06-20T14:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem setting up a U-Turn NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29662#M21671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to confirm, I think your oscp.company.com resolves to the loopback address 10.99.99.1 in your diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, I think your rules need to have 10.99.99.1 as the destination address and then put 100.1.1.1 as the translated destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;keep the source translation as it is now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are basically doing a double nat on both source and destination to create the U-turn for your setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Jun 2014 11:42:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29662#M21671</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-06-21T11:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem setting up a U-Turn NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29663#M21672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for my late reply on this. I was too busy with other tasks unfortunately. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're right tpiens, the loopback interface is in the External zone. When I removed the SNAT entry, it worked like a charm!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your hint.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jul 2014 09:34:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29663#M21672</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2014-07-02T09:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Problem setting up a U-Turn NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29664#M21673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your post Steven. The DNS name "ocsp.company.com" resolves to an external IP on internal clients as well. We do have other situations where we actually do use the internal IP address of a loopback interface when we access it from a trusted zone. There we have Split-DNS active. On the setup described here we don't have Split-DNS available which finally caused the issue. Now that this is resolved we're good to go ahead. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jul 2014 09:39:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29664#M21673</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2014-07-02T09:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Problem setting up a U-Turn NAT rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29665#M21674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to hear you have this working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jul 2014 11:13:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-setting-up-a-u-turn-nat-rule/m-p/29665#M21674</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-07-02T11:13:08Z</dc:date>
    </item>
  </channel>
</rss>

