<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN w/ NAT on external IP in same range as VPN IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-w-nat-on-external-ip-in-same-range-as-vpn-ip/m-p/30677#M22459</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;maybe that title was convoluted but i need some feedback for somethiung i have not done before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;setting up a VPN but the other party says they DO NOT allow internal addreses over the VPN to their network; so i cant give them proxy IDs of 192.168.0.0 10.0.0.0 etc... it has to be an internet routable IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont have any proxy IDs&lt;/P&gt;&lt;P&gt;Im using an external internet routable IP from the same range im using to setup the VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eg:&lt;/P&gt;&lt;P&gt;IP for VPN: &lt;STRONG&gt;5.5.5.5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;IP for "interesting traqffic (IP i will send packets with): &lt;STRONG&gt;5.5.5.4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will NAT the traffic out 5.5.5.4 while the 5.5.5.5 is used for the VPN tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to use the same IP for both the VPN and the interesting traffic IP but the PA would not let me commit that, thats fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this going to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ony have one chance to get this right before there is a change freeze over the holidays.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Dec 2013 19:57:31 GMT</pubDate>
    <dc:creator>choff123</dc:creator>
    <dc:date>2013-12-12T19:57:31Z</dc:date>
    <item>
      <title>VPN w/ NAT on external IP in same range as VPN IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-w-nat-on-external-ip-in-same-range-as-vpn-ip/m-p/30677#M22459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;maybe that title was convoluted but i need some feedback for somethiung i have not done before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;setting up a VPN but the other party says they DO NOT allow internal addreses over the VPN to their network; so i cant give them proxy IDs of 192.168.0.0 10.0.0.0 etc... it has to be an internet routable IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont have any proxy IDs&lt;/P&gt;&lt;P&gt;Im using an external internet routable IP from the same range im using to setup the VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eg:&lt;/P&gt;&lt;P&gt;IP for VPN: &lt;STRONG&gt;5.5.5.5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;IP for "interesting traqffic (IP i will send packets with): &lt;STRONG&gt;5.5.5.4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will NAT the traffic out 5.5.5.4 while the 5.5.5.5 is used for the VPN tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to use the same IP for both the VPN and the interesting traffic IP but the PA would not let me commit that, thats fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this going to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ony have one chance to get this right before there is a change freeze over the holidays.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 19:57:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-w-nat-on-external-ip-in-same-range-as-vpn-ip/m-p/30677#M22459</guid>
      <dc:creator>choff123</dc:creator>
      <dc:date>2013-12-12T19:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN w/ NAT on external IP in same range as VPN IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-w-nat-on-external-ip-in-same-range-as-vpn-ip/m-p/30678#M22460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;choff123,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just performed a quick lab of your requirement and this requirement would work just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no special caveats that I needed to put in place to get this working. I only needed to configure a bi-direction NAT for my real private interesting traffic and the NAT'd IP that would go over the tunnel; 5.5.5.4 in your case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you run into any problems performing this in your environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;tasonibare&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 23:13:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-w-nat-on-external-ip-in-same-range-as-vpn-ip/m-p/30678#M22460</guid>
      <dc:creator>tasonibare</dc:creator>
      <dc:date>2013-12-12T23:13:21Z</dc:date>
    </item>
  </channel>
</rss>

