<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT based on URL or FQDN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-based-on-url-or-fqdn/m-p/31710#M23191</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The NAT rule can be specified for Destination Address Object, which can be configured to be an FQDN address object. This setting should work as long as the Palo Alto is able to do a FQDN lookup succesfully for the specified FQDN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, as long as the FQDN resolves to the same IP you may not be able to have them translated to different Inside servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason being, if multiple FQDNs resolve to the same Public IP, having different NAT rules will create a conflict when setting the NAT rule. The firewall irrespective of whether we have the FQDN or actual IP will still store the IP in the running config, having multiple NAT rules with the same Ip will create a conflict.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Oct 2013 23:42:17 GMT</pubDate>
    <dc:creator>Chatri</dc:creator>
    <dc:date>2013-10-30T23:42:17Z</dc:date>
    <item>
      <title>NAT based on URL or FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-based-on-url-or-fqdn/m-p/31709#M23190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I want to make a NAT based on a URL or FQDN.&lt;/P&gt;&lt;P&gt;I only have one public IP but several URL that I want to NAT to different inside servers.&lt;/P&gt;&lt;P&gt;I have this working on a ISA and want to do the same in the PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PA 500 with 5.0.8.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 17:35:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-based-on-url-or-fqdn/m-p/31709#M23190</guid>
      <dc:creator>jose.chaves</dc:creator>
      <dc:date>2013-10-30T17:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on URL or FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-based-on-url-or-fqdn/m-p/31710#M23191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The NAT rule can be specified for Destination Address Object, which can be configured to be an FQDN address object. This setting should work as long as the Palo Alto is able to do a FQDN lookup succesfully for the specified FQDN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, as long as the FQDN resolves to the same IP you may not be able to have them translated to different Inside servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason being, if multiple FQDNs resolve to the same Public IP, having different NAT rules will create a conflict when setting the NAT rule. The firewall irrespective of whether we have the FQDN or actual IP will still store the IP in the running config, having multiple NAT rules with the same Ip will create a conflict.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 23:42:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-based-on-url-or-fqdn/m-p/31710#M23191</guid>
      <dc:creator>Chatri</dc:creator>
      <dc:date>2013-10-30T23:42:17Z</dc:date>
    </item>
  </channel>
</rss>

