<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with interzone U turn NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-interzone-u-turn-nat/m-p/3286#M2453</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed the instructions in the paloalto "understanding NAT-4.1RevC" pdf for implementing U turn NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works when I try to access a server in the DMZ from the trusted zone via it's public untrusted IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have now a web server which somehow tries to do a http connect to it's own URL, which describes Case 5 in this document "server in the same zone as the client"&lt;/P&gt;&lt;P&gt;I followed the instructions:&lt;/P&gt;&lt;P&gt;NAT rule: DMZ-Zone to Untrust Zone with destination public IP translated to private IP and source translated to untrusted Interface and IP. I even created a security policy although the document says it is not needed as the traffic is in the same zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that I can't get it working the connection always times out, the same when I try to access the Public IP from an other server in the DMZ. I worked around the problem by setting up a DNS in the DMZ which points the URL to the servers private IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't see any traffic in the traffic logs which is probably due to the inter zone traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone an idea why this isn't working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Jan 2013 10:00:35 GMT</pubDate>
    <dc:creator>saint-paul</dc:creator>
    <dc:date>2013-01-31T10:00:35Z</dc:date>
    <item>
      <title>Problem with interzone U turn NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-interzone-u-turn-nat/m-p/3286#M2453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed the instructions in the paloalto "understanding NAT-4.1RevC" pdf for implementing U turn NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works when I try to access a server in the DMZ from the trusted zone via it's public untrusted IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have now a web server which somehow tries to do a http connect to it's own URL, which describes Case 5 in this document "server in the same zone as the client"&lt;/P&gt;&lt;P&gt;I followed the instructions:&lt;/P&gt;&lt;P&gt;NAT rule: DMZ-Zone to Untrust Zone with destination public IP translated to private IP and source translated to untrusted Interface and IP. I even created a security policy although the document says it is not needed as the traffic is in the same zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that I can't get it working the connection always times out, the same when I try to access the Public IP from an other server in the DMZ. I worked around the problem by setting up a DNS in the DMZ which points the URL to the servers private IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't see any traffic in the traffic logs which is probably due to the inter zone traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone an idea why this isn't working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 10:00:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-interzone-u-turn-nat/m-p/3286#M2453</guid>
      <dc:creator>saint-paul</dc:creator>
      <dc:date>2013-01-31T10:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with interzone U turn NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-interzone-u-turn-nat/m-p/3287#M2454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...Please try changing the source NAT from 'untrusted Interface and IP' to the interface and IP of the DMZ-zone.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 19:04:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-interzone-u-turn-nat/m-p/3287#M2454</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2013-02-01T19:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with interzone U turn NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-interzone-u-turn-nat/m-p/3288#M2455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, this solved the problem. &lt;/P&gt;&lt;P&gt;I had some strange glitch that the nat rule wouldn't accept to IP of the interface, it always reset to "none". I had to delete the rule and recreate it, after that I had to move the NAT rule up as it was shadowed by an other rule. It then finally worked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 14:18:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-interzone-u-turn-nat/m-p/3288#M2455</guid>
      <dc:creator>saint-paul</dc:creator>
      <dc:date>2013-02-04T14:18:14Z</dc:date>
    </item>
  </channel>
</rss>

