<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Destination: Public IP that NATs to DMZ private IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/destination-public-ip-that-nats-to-dmz-private-ip/m-p/302#M251</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you're describing is what we call "U-Turn NAT". There is a great document called understanding NAT and it seems to cover your questions and should help you in creating your security policies and NAT policies for this particular type of NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=dl_tech_doc&amp;amp;filename=Understanding-NAT.pdf"&gt;https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=dl_tech_doc&amp;amp;filename=Understanding-NAT.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Page 27 begins the U-Turn NAT discussion and examples. (With Screenshots)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If for some reason the link above doesn't work, the document can be found on the support portal under technical documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Jason Seals &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Mar 2012 04:47:39 GMT</pubDate>
    <dc:creator>jseals</dc:creator>
    <dc:date>2012-03-22T04:47:39Z</dc:date>
    <item>
      <title>Destination: Public IP that NATs to DMZ private IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-public-ip-that-nats-to-dmz-private-ip/m-p/301#M250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to get a better understanding of how a specific request is completed. If an internal private IP, say 10.10.10.20 leaves the provate network behind an IP of 2.2.2.2 and heads to the Internet fine then tries to go to an IP which the firewall NATs, such as 2.2.2.3 to a DMZ IP of 10.10.50.20. What is the source for the packet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the firewall consider the packet from 10.10.10.20 as having really gone straight to 10.10.50.20 and do no address translation? If it's really gone out and back in, then surely 10.10.50.20 would get a source address for the inbound packet as 2.2.2.2 (the IP that the general inside traffic goes out behind).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clarification of all this would be very useful to me in troubleshooting an ongoing issue I have with inside devices contacting a DMZ device by it's external IP, and currently failing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;UKRB.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2012 00:12:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-public-ip-that-nats-to-dmz-private-ip/m-p/301#M250</guid>
      <dc:creator>UKRB</dc:creator>
      <dc:date>2012-03-22T00:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Destination: Public IP that NATs to DMZ private IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-public-ip-that-nats-to-dmz-private-ip/m-p/302#M251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you're describing is what we call "U-Turn NAT". There is a great document called understanding NAT and it seems to cover your questions and should help you in creating your security policies and NAT policies for this particular type of NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=dl_tech_doc&amp;amp;filename=Understanding-NAT.pdf"&gt;https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=dl_tech_doc&amp;amp;filename=Understanding-NAT.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Page 27 begins the U-Turn NAT discussion and examples. (With Screenshots)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If for some reason the link above doesn't work, the document can be found on the support portal under technical documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Jason Seals &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2012 04:47:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-public-ip-that-nats-to-dmz-private-ip/m-p/302#M251</guid>
      <dc:creator>jseals</dc:creator>
      <dc:date>2012-03-22T04:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: Destination: Public IP that NATs to DMZ private IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-public-ip-that-nats-to-dmz-private-ip/m-p/303#M252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are basically describing a u-turn NAT scenario. Have a look at below article as it could help to understand how this scenario works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1678"&gt;https://live.paloaltonetworks.com/docs/DOC-1678&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may also find below Tech Note useful as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=dl_tech_doc&amp;amp;filename=Understanding-NAT.pdf"&gt;&lt;SPAN style="color: #355491; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif; "&gt;https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=dl_tech_doc&amp;amp;filename=Understanding-NAT.pdf&lt;/SPAN&gt; &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2012 04:53:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-public-ip-that-nats-to-dmz-private-ip/m-p/303#M252</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-03-22T04:53:15Z</dc:date>
    </item>
  </channel>
</rss>

