<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Shared Gateway and VSYS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/shared-gateway-and-vsys/m-p/31294#M22883</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've a basic setup with TWO vsys with separate vrouters on each vsys (Maketing and Sales ) and a shared Gateway. Some vpn Tunnels terminating on my shared gateway.&lt;/P&gt;&lt;P&gt;I need to implement some static NAT rules for my VPN tunnels, so far so good.&lt;/P&gt;&lt;P&gt;Routing 0.0.0.0/0 goes to the Shared gateway and of course other locally routes are routed locally by Vrouter on their respective Vsys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But some address should be NAted before/through the VPN tunnel, which I thought should be configured on the shared gateway .But it doesn't work that way. I need to implement NAT rules on the MArketing or Sales Vsys.&lt;/P&gt;&lt;P&gt;Even a route from VSYS with destination the NAT address subnet towards vrouter of the Shared gateway doesn't seem to be cathed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VIRTUAL ROUTER: RTVOUT01 (id 2)&lt;BR /&gt;&amp;nbsp; ==========&lt;BR /&gt;destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nexthop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; metric flags&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; age&amp;nbsp;&amp;nbsp; interface&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; next-AS&lt;BR /&gt;10.14.6.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vr VR-SGOUT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A S&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when you perform a routing test ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;run test routing fib-lookup ip 10.14.6.1 virtual-router RTVOUT01&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;runtime route lookup&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;virtual-router:&amp;nbsp;&amp;nbsp; RTVOUT01&lt;BR /&gt;destination:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.14.6.1&lt;BR /&gt;result:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; route not found&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found on KB of Palo Alto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Update: Fixed in 4.0.8&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;there seem to be a problem with version 4.1 .&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Question: Would it be advisable to integrate a Shared Gateway into another VSYS ( INTERNET) with his vrouter and interfaces attached ? Because now the Shared Gateway isn't attached to a VSYS ..&lt;/P&gt;&lt;P class="MsoNormal"&gt;Would the function shared gateway still work ?&lt;/P&gt;&lt;P class="MsoNormal"&gt;In the documentation the shared gateway only has the NAT possibility. If I attach it to a VSYS I suppose I do have Security and NAT policies ??&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Thanks for any input ..&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 May 2012 08:49:53 GMT</pubDate>
    <dc:creator>slh</dc:creator>
    <dc:date>2012-05-11T08:49:53Z</dc:date>
    <item>
      <title>Shared Gateway and VSYS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shared-gateway-and-vsys/m-p/31294#M22883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've a basic setup with TWO vsys with separate vrouters on each vsys (Maketing and Sales ) and a shared Gateway. Some vpn Tunnels terminating on my shared gateway.&lt;/P&gt;&lt;P&gt;I need to implement some static NAT rules for my VPN tunnels, so far so good.&lt;/P&gt;&lt;P&gt;Routing 0.0.0.0/0 goes to the Shared gateway and of course other locally routes are routed locally by Vrouter on their respective Vsys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But some address should be NAted before/through the VPN tunnel, which I thought should be configured on the shared gateway .But it doesn't work that way. I need to implement NAT rules on the MArketing or Sales Vsys.&lt;/P&gt;&lt;P&gt;Even a route from VSYS with destination the NAT address subnet towards vrouter of the Shared gateway doesn't seem to be cathed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VIRTUAL ROUTER: RTVOUT01 (id 2)&lt;BR /&gt;&amp;nbsp; ==========&lt;BR /&gt;destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nexthop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; metric flags&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; age&amp;nbsp;&amp;nbsp; interface&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; next-AS&lt;BR /&gt;10.14.6.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vr VR-SGOUT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A S&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when you perform a routing test ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;run test routing fib-lookup ip 10.14.6.1 virtual-router RTVOUT01&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;runtime route lookup&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;virtual-router:&amp;nbsp;&amp;nbsp; RTVOUT01&lt;BR /&gt;destination:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.14.6.1&lt;BR /&gt;result:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; route not found&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found on KB of Palo Alto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Update: Fixed in 4.0.8&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;there seem to be a problem with version 4.1 .&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Question: Would it be advisable to integrate a Shared Gateway into another VSYS ( INTERNET) with his vrouter and interfaces attached ? Because now the Shared Gateway isn't attached to a VSYS ..&lt;/P&gt;&lt;P class="MsoNormal"&gt;Would the function shared gateway still work ?&lt;/P&gt;&lt;P class="MsoNormal"&gt;In the documentation the shared gateway only has the NAT possibility. If I attach it to a VSYS I suppose I do have Security and NAT policies ??&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Thanks for any input ..&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2012 08:49:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shared-gateway-and-vsys/m-p/31294#M22883</guid>
      <dc:creator>slh</dc:creator>
      <dc:date>2012-05-11T08:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Shared Gateway and VSYS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shared-gateway-and-vsys/m-p/31295#M22884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick, what are you specific requirements with regards to applying NAT prior to your traffic ingressing your tunnel interface for VPN traversal?&amp;nbsp; Do you need to perform source translation, destination translation, or both?&amp;nbsp; Can you provide more details regarding your requirements or perhaps a specific example?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you,&lt;/P&gt;&lt;P&gt;-Bryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2012 01:01:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shared-gateway-and-vsys/m-p/31295#M22884</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2012-05-31T01:01:35Z</dc:date>
    </item>
  </channel>
</rss>

