<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Communication Problem between Lan and DMZ in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/communication-problem-between-lan-and-dmz/m-p/34738#M25493</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Veera,&lt;/P&gt;&lt;P&gt;all of what you have described are basic functions of the Paloalto device. So they should work just fine.&lt;/P&gt;&lt;P&gt;As long as you have policies to allow traffic from the trust to dmz or dmz to trust and routing is correct, this should work.&lt;/P&gt;&lt;P&gt;Also sharing should work fine especially if ftp and ping work.&lt;/P&gt;&lt;P&gt;Perhaps you can create a policy for all traffic between the trust and dmz and the dmz and trust, allowing all applications and services.&lt;/P&gt;&lt;P&gt;If committting this policy resolves your issues then you know that perhaps your were not allowing all the necessary applications and services. However if your problems still persist, you can call into support in order that we can take a closer look at your device configuration and network configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Jun 2010 16:23:11 GMT</pubDate>
    <dc:creator>swhyte</dc:creator>
    <dc:date>2010-06-08T16:23:11Z</dc:date>
    <item>
      <title>Communication Problem between Lan and DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-problem-between-lan-and-dmz/m-p/34735#M25490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; We have PAN 500 device with us..deployed in L3 mode.Lan and DMZ communication is happening only if i have NAT rule in place with the destination zone and interface mentioned (but no natting be done)between them.Do we really require a NAT rule in place for achieving this.I guess this doesn't require.We have tested with all OS and models.Anyone faced this issue earlier?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jun 2010 10:28:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-problem-between-lan-and-dmz/m-p/34735#M25490</guid>
      <dc:creator>veera12883</dc:creator>
      <dc:date>2010-06-08T10:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Communication Problem between Lan and DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-problem-between-lan-and-dmz/m-p/34736#M25491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Veera,&lt;/P&gt;&lt;P&gt;NAT is not need is your routing is set up correctly.&lt;/P&gt;&lt;P&gt;So if you have a l3 lan interface connected to the same virtual router that a l3 dmz interface is connected to, you should be able to route between them. However if each network does not know how to route back to the other, then you can use a NAT rule to work around your routing problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jun 2010 14:54:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-problem-between-lan-and-dmz/m-p/34736#M25491</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-06-08T14:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Communication Problem between Lan and DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-problem-between-lan-and-dmz/m-p/34737#M25492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi STEPHEN,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have both the DMZ&amp;nbsp; and trust in the same virtual router and proper routing is there,but the communication is happening only when we have the NAT policy in place.Also sometimes ping,FTP and other services are working but file sharing is not happening,this also only for few users. Have this been replicated in labs and any issues faced earlier?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;veera&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jun 2010 16:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-problem-between-lan-and-dmz/m-p/34737#M25492</guid>
      <dc:creator>veera12883</dc:creator>
      <dc:date>2010-06-08T16:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Communication Problem between Lan and DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-problem-between-lan-and-dmz/m-p/34738#M25493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Veera,&lt;/P&gt;&lt;P&gt;all of what you have described are basic functions of the Paloalto device. So they should work just fine.&lt;/P&gt;&lt;P&gt;As long as you have policies to allow traffic from the trust to dmz or dmz to trust and routing is correct, this should work.&lt;/P&gt;&lt;P&gt;Also sharing should work fine especially if ftp and ping work.&lt;/P&gt;&lt;P&gt;Perhaps you can create a policy for all traffic between the trust and dmz and the dmz and trust, allowing all applications and services.&lt;/P&gt;&lt;P&gt;If committting this policy resolves your issues then you know that perhaps your were not allowing all the necessary applications and services. However if your problems still persist, you can call into support in order that we can take a closer look at your device configuration and network configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jun 2010 16:23:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-problem-between-lan-and-dmz/m-p/34738#M25493</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-06-08T16:23:11Z</dc:date>
    </item>
  </channel>
</rss>

