<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: no nat in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32710#M23964</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i can't deploy it in vwire, cause i have to manage acces between internal zones &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Jul 2013 13:44:10 GMT</pubDate>
    <dc:creator>atelcom</dc:creator>
    <dc:date>2013-07-08T13:44:10Z</dc:date>
    <item>
      <title>no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32707#M23961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Arial','sans-serif'; color: black;"&gt;hello &lt;BR /&gt; &lt;BR /&gt; i'am configuring a paloalto firwall wish is the backward firewall, &lt;BR /&gt; &lt;BR /&gt; i'm facing problem with nat , users must be integrated in the frontal firewall &lt;BR /&gt; &lt;BR /&gt; users passes by paloalto firewall first then the frontal firewall, when it pass by pan their adresses changes by nat , and the frontal firewall does'nt reconginze them ,wish is a hige problem &lt;BR /&gt; &lt;BR /&gt; i tried to delete nat because the outside interface of pan is also a private adress , but traffic don't pass when i do this &lt;BR /&gt; &lt;BR /&gt; so i want toknow if i can allow traffic to pass without nating , or if pan has someting called (no nat) like asa and juniper &lt;BR /&gt; &lt;BR /&gt; please help me to figure it out &lt;BR /&gt; &lt;BR /&gt; thank's in advance &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 09:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32707#M23961</guid>
      <dc:creator>atelcom</dc:creator>
      <dc:date>2013-07-08T09:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32708#M23962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Atelcom,&lt;/P&gt;&lt;P&gt;We do have an option to skip the NAT translation. You can specify the source address ( subnet ), the source Zone, The destination address ( subnet ) and the destination zone, and under the "Translated Packet section" select the translation type to "None", as shown in the attachment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="no-nat.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7212_no-nat.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is as good as not configuring a NAT policy at all. So all you need is a security policy from the inside zone of the PANFW to the outside zone of the PANFW. &lt;/P&gt;&lt;P&gt;You could also have a v-wire deployment on the PANFW, if the PANFW isnt on the perimeter, and use it as an IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and best regards,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 12:45:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32708#M23962</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-07-08T12:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32709#M23963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank's for your return, i did try the none nat like shown in the attachement , for any source and any destination ..but it doesn't work &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i try also to delete it , and the traffic don't pass neither&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 13:43:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32709#M23963</guid>
      <dc:creator>atelcom</dc:creator>
      <dc:date>2013-07-08T13:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32710#M23964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i can't deploy it in vwire, cause i have to manage acces between internal zones &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 13:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32710#M23964</guid>
      <dc:creator>atelcom</dc:creator>
      <dc:date>2013-07-08T13:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32711#M23965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Atelcom,&lt;/P&gt;&lt;P&gt;Can you attach the screenshots of the NAT policy and the security policy in question&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 13:58:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32711#M23965</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-07-08T13:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32712#M23966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;currently i'm not at the customer and i can't access to the appliance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 14:13:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32712#M23966</guid>
      <dc:creator>atelcom</dc:creator>
      <dc:date>2013-07-08T14:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32713#M23967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="Capture-pan.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7260_Capture-pan.PNG" width="450" /&gt;&lt;IMG alt="Capture-rule-pan.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7261_Capture-rule-pan.PNG" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jul 2013 08:49:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32713#M23967</guid>
      <dc:creator>atelcom</dc:creator>
      <dc:date>2013-07-15T08:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32714#M23968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="Capture-nat.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7262_Capture-nat.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;t tried also this, but it still does'nt work .should i add another think like an additionnal route to get it work&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jul 2013 08:51:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32714#M23968</guid>
      <dc:creator>atelcom</dc:creator>
      <dc:date>2013-07-15T08:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32715#M23969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case ,it seems PA firewall is acting a Pass-through in L3 mode and the upstream "&lt;STRONG&gt; frontal"&lt;/STRONG&gt; firewall is taking care of source-NAT for internet traffic.&lt;/P&gt;&lt;P&gt;Source-NAT on PA (if configured)&amp;nbsp; would take care of the Return route to Inside Network, but if NAT is not needed,make sure the &lt;STRONG&gt;"frontal"&lt;/STRONG&gt; firewall has a route to the LAN/inside network with PA as a next-hop.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jul 2013 09:21:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32715#M23969</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-15T09:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32716#M23970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Nadir,&lt;/P&gt;&lt;P&gt;thank's for your return it was very helpful, i added a return route in the frontal firewall, and all seems to work fine&lt;/P&gt;&lt;P&gt;but i didn't inderstand the concept, why it doesn't reconizne traffic , it must be stateful firewall so it keep session table&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank's in advance &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 12:30:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32716#M23970</guid>
      <dc:creator>atelcom</dc:creator>
      <dc:date>2013-07-16T12:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: no nat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32717#M23971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you have introduced a new L3 Device (PA FW) in the Network. The Frontal firewall does not know how to route back the return traffic.&lt;/P&gt;&lt;P&gt;Source-NAT on PA firewall was taking care of this return route earlier. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 13:04:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-nat/m-p/32717#M23971</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-16T13:04:42Z</dc:date>
    </item>
  </channel>
</rss>

