<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Combined source &amp; destination NAT in one rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31869#M23326</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Absolutely - no problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Oct 2010 18:31:54 GMT</pubDate>
    <dc:creator>kbrazil</dc:creator>
    <dc:date>2010-10-29T18:31:54Z</dc:date>
    <item>
      <title>Combined source &amp; destination NAT in one rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31868#M23325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you perform source AND destination address translation on a single packet? I know NAT rule processing is first rule match so more specifically, can I have a single NAT rule that defines a source and destination translation?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 18:06:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31868#M23325</guid>
      <dc:creator>plago</dc:creator>
      <dc:date>2010-10-29T18:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Combined source &amp; destination NAT in one rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31869#M23326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Absolutely - no problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 18:31:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31869#M23326</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-10-29T18:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Combined source &amp; destination NAT in one rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31870#M23327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the quick response Kelly. Are there any plans to allows multi-NAT rule matching? I don't need it now but wondering if it in the plans?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 19:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31870#M23327</guid>
      <dc:creator>plago</dc:creator>
      <dc:date>2010-10-29T19:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Combined source &amp; destination NAT in one rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31871#M23328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is not currently on the roadmap.&amp;nbsp; Let us know if you have a particular use-case for the feature - we may be able to find a workaround or enter a feature request.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this time all of the rule bases behave as top-down ordering and first match complete.&amp;nbsp; One subtlety is the Security Rulebase, where the rulebase can be checked multiple times if the application changes mid-session, but it is still top-down ordering and first match complete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 19:09:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31871#M23328</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-10-29T19:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Combined source &amp; destination NAT in one rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31872#M23329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to followup on this back of this request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I too have a requirement for a double NAT entry where by I wish to change the source and destination address of a particular traffic pattern.Here is the scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to advertise a service that is routable using a private side/trusted ip address obtained from within subnet range of the private side interface of the firewall. For example;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The trusted side interface and zone of the firewall is;&lt;/P&gt;&lt;P&gt;L3-PRIV = 172.16.227.254/22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then create a loopback address which is also assigned to the same zone using a subnet range as follows&lt;/P&gt;&lt;P&gt;L3-PRIV = 172.16.245.33/27&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a network service that is reachable through a DMZ (untrusted interface) and then via a next hop router.&lt;/P&gt;&lt;P&gt;The remote network is routed via the virtual routing table used by both layer 3 interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want clients that hit the destination address equal to loopback address of 172.16.245.33/27 to be translated using this soruce and also have the destiantion translated to a new destiantion address routable via my DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Summary&lt;/P&gt;&lt;P&gt;Origianl Packet SRC_ZONE=L3-PRIV - SRC_IP = 192.168.230.10/24 - NAT'd SRC_ZONE=L3-PRIV SRC_IP=172.16.245.33/27&lt;/P&gt;&lt;P&gt;Original Packet DST_ZONE=L3_PRIV - DST_IP = 172.16.245.33/27&amp;nbsp;&amp;nbsp; - NAT'd DST_ZONE=L3-DMZ DST_IP=10.142.210.5/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this make sense and is this possible? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The use case is that the destination network will only be aware of the loopback address subnet from a routing perspective, plus the clients on my internal network can reach the loopback address, but not the true destination hence the need for a destination NAT. Traffic will always be initiated from the trusted side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 14:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31872#M23329</guid>
      <dc:creator>technicalsupport</dc:creator>
      <dc:date>2011-08-08T14:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Combined source &amp; destination NAT in one rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31873#M23330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Please read the KP article for U-Turn NAT.&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1678"&gt;https://live.paloaltonetworks.com/docs/DOC-1678&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It documents how to build two NAT rules for accessing the same public server.&lt;/P&gt;&lt;P&gt;Rule 1 - One to One nat for the outside world when they use the FQDN for access.&lt;/P&gt;&lt;P&gt;Rule 2 - Src and Dest nat when a user on trusted side tries to use the same FQDN URL to access the same server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Aug 2011 21:12:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/31873#M23330</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-08-15T21:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Combined source &amp; destination NAT in one rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/529106#M109234</link>
      <description>&lt;P&gt;Dear Kbrazil,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to request to help investigate my issues, Currently I'm facing with DNAT policy issues. My design is pointing to DUAL Internet user can access to my DMZ network, My current policy and NAT translation is pointing to&amp;nbsp; ISP1 and destination translation IP is 10.101.7.9 this policy working fine and that I can confirm with the hits count for this policy. The problem is when ISP1 down our outside user cannot access the DMZ network, So, I decide to create duplicate the old policy and pointing to ISP2 and destination translation IP also 10.101.7.9. This policy is doesn't work and cannot access from internet. Hits count also 0 for this policy. So, how can i solve the issues please kindly suggests my issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance,&lt;/P&gt;
&lt;P&gt;Pyie Phyo Htay.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 04:34:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combined-source-destination-nat-in-one-rule/m-p/529106#M109234</guid>
      <dc:creator>PyiePhyoHtay</dc:creator>
      <dc:date>2023-01-30T04:34:23Z</dc:date>
    </item>
  </channel>
</rss>

