<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT for ldap in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-for-ldap/m-p/31526#M23064</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. Do I need to create each of the 10 IP addresses manually/individually in the PAN first or on the fly as part of the rule?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Aug 2013 20:26:09 GMT</pubDate>
    <dc:creator>jpzynski</dc:creator>
    <dc:date>2013-08-01T20:26:09Z</dc:date>
    <item>
      <title>NAT for ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-for-ldap/m-p/31524#M23062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to configure my PAN to allow LDAP and port 636 inbound from 10 specific IP addresses for authentication with a software company. Can't figure out how to do this correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 20:04:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-for-ldap/m-p/31524#M23062</guid>
      <dc:creator>jpzynski</dc:creator>
      <dc:date>2013-08-01T20:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAT for ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-for-ldap/m-p/31525#M23063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;You can write a Destination NAT with the source IP address as the 10 IP adresses, the source zone as "untrust",&amp;nbsp; the destination address with the public IP address of the ldap server, the destination zone as "untrust", service as 636 under the original packet section. Under the translated packet section, click on the check box of the "destination address translation" and give the private IP address of the ldap server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Write a corresponding security rule with the source IP address as these 10 IP addresses, the source zone as "untrust", the destination IP address as the "public IP address of the server", the destination zone as "trust ( or DMZ, where the server is located), application = LDAP, service =any, and action= allow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 20:21:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-for-ldap/m-p/31525#M23063</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-01T20:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: NAT for ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-for-ldap/m-p/31526#M23064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. Do I need to create each of the 10 IP addresses manually/individually in the PAN first or on the fly as part of the rule?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 20:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-for-ldap/m-p/31526#M23064</guid>
      <dc:creator>jpzynski</dc:creator>
      <dc:date>2013-08-01T20:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT for ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-for-ldap/m-p/31527#M23065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could create address objects for these IP addresses, and use these address objects under the NAT and the security rules,if you want to identify the users based on a string / identity. You also have an option of adding these IP addresses on the fly when creating the new rules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 20:33:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-for-ldap/m-p/31527#M23065</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-01T20:33:05Z</dc:date>
    </item>
  </channel>
</rss>

