<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Natting Internal Hosts to a differente ISP`s in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3322#M2479</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Friento , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i acess the PALO ALTO GUI from the second ISP , i can acess normally the GUI , So i think the Internet router are working good.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Tks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Mar 2012 19:35:22 GMT</pubDate>
    <dc:creator>Thiago</dc:creator>
    <dc:date>2012-03-20T19:35:22Z</dc:date>
    <item>
      <title>Natting Internal Hosts to a differente ISP`s</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3317#M2474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to find documentation and/or any help to see if PAN firewalls are capable of NATing Two external ISP`s to a differents hosts IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My default gateway is 187.x.x.x&lt;/P&gt;&lt;P&gt;When i try to make a NAT with the seconde ISP 189.x.x.x , i don`t know but don`t work.&lt;/P&gt;&lt;P&gt;When i send a netstat at my HOST on NAT , the server don`t receive the SYN to start the handshake.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP1 187.x.x.x &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------&amp;gt; Internal hosts 10.55.x.x&lt;/P&gt;&lt;P&gt;ISP2 189.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2012 19:40:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3317#M2474</guid>
      <dc:creator>Thiago</dc:creator>
      <dc:date>2012-03-19T19:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Internal Hosts to a differente ISP`s</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3318#M2475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to setup PBR (Policy Based Routing) sometimes called PBF (Policy Based Forwarding) to force for example specific clients to use specific uplink.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise it should work with two different metrics since PAN current doesnt support ECMP (Equal Cost MultiPath routing).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above is for SNAT (Source NAT).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For DNAT (Destiantion NAT) its just as always, you need to specify which host on the inside should get the traffic (watch out so PBR/PBF doesnt make the returntraffic go assymetric, like client sends traffic to ISP1IP:80 but get answers from ISP2IP:80 which of course will be dropped at the clientside).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2012 21:09:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3318#M2475</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-19T21:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Internal Hosts to a differente ISP`s</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3319#M2476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok , thank u for your fast answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to understand about DNAT , when i look at my server with a NETSTAT i can`t see any SYN connection.&lt;/P&gt;&lt;P&gt;THis happen because when my server try to response to the SYN&amp;nbsp; , it goes assymetric ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2012 14:20:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3319#M2476</guid>
      <dc:creator>Thiago</dc:creator>
      <dc:date>2012-03-20T14:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Internal Hosts to a differente ISP`s</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3320#M2477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Personally I would use tcpdump either on the server or by using a spanport on the switch which this server is connected to in order to find out what is actually being transmitted to the server (and how this packet looks like) and whats being returned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then do the same on a spanport on the internetrouter to find out how the packets looks like when leaving PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Netstat I think it will only display "Established" for sessions who completely went through the 3-way handshake. Otherwise it will display Waiting or similar.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2012 17:55:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3320#M2477</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-20T17:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Internal Hosts to a differente ISP`s</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3321#M2478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;make sure that your internet router is sending traffic to your firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2012 18:04:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3321#M2478</guid>
      <dc:creator>friento</dc:creator>
      <dc:date>2012-03-20T18:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Internal Hosts to a differente ISP`s</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3322#M2479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Friento , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i acess the PALO ALTO GUI from the second ISP , i can acess normally the GUI , So i think the Internet router are working good.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Tks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2012 19:35:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-internal-hosts-to-a-differente-isp-s/m-p/3322#M2479</guid>
      <dc:creator>Thiago</dc:creator>
      <dc:date>2012-03-20T19:35:22Z</dc:date>
    </item>
  </channel>
</rss>

