<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Over IPSEC VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34948#M25654</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/16949"&gt;BFCBahrain&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your destination NAT, your destination zone should still be VPN zone in your original packet. Your security rule would be from VPN to DMZ zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can refer to the following document for the same scenario on page 15-18 :&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;Understanding PAN-OS NAT&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Dec 2013 19:42:20 GMT</pubDate>
    <dc:creator>kadak</dc:creator>
    <dc:date>2013-12-06T19:42:20Z</dc:date>
    <item>
      <title>NAT Over IPSEC VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34947#M25653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing a problem with NAT over IPSEC VPN.&lt;/P&gt;&lt;P&gt;I am trying to configure the NAt for incoming traffic from the client over a site to site VPN and basically i want to do a destination translation of the IP they access to my internal server IP.&lt;/P&gt;&lt;P&gt;The Client is in VPN zone and my server sits in the DMZ&lt;/P&gt;&lt;P&gt;I configured Rule like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source zone(VPN)-Source IP(Client IP )- Destination Zone(DMZ) -Destination IP(Nated IP) -&amp;gt; NAT -Selected only destination&amp;nbsp; NAT that translate the NAted IP to my DMZ Server IP.&lt;/P&gt;&lt;P&gt;After doing this ,I don't see traffic hitting my firewall .I don't think this could be problem on the VPN as the other traffic over this VPN is working fine .&lt;/P&gt;&lt;P&gt;Issue happens only when I introduce this NAT ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can Anyone help here ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 17:38:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34947#M25653</guid>
      <dc:creator>BFCBahrain</dc:creator>
      <dc:date>2013-12-06T17:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Over IPSEC VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34948#M25654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/16949"&gt;BFCBahrain&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your destination NAT, your destination zone should still be VPN zone in your original packet. Your security rule would be from VPN to DMZ zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can refer to the following document for the same scenario on page 15-18 :&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;Understanding PAN-OS NAT&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 19:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34948#M25654</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-12-06T19:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Over IPSEC VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34949#M25655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot Kadak.&lt;/P&gt;&lt;P&gt;I have trired this from VPN to VPN and it did not help..&lt;/P&gt;&lt;P&gt;I have referred the doc and it points to another doc for NAT with VPN&lt;/P&gt;&lt;P&gt;Pleae check the page 9 of this and it says NAT rule is from VPN to Trust&amp;nbsp; !!&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1594"&gt;https://live.paloaltonetworks.com/docs/DOC-1594&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look at the below link where it says Policy should be from VPN to Untrust .&lt;/P&gt;&lt;P&gt;I tried this also and it did not help .I have an Untrust Zone where I have 2 ISPs are residing on it on 2 Virtual Interfaces.&lt;/P&gt;&lt;P&gt;1/1.1 and 1/1.2&amp;nbsp; .both are in Untrust-ISP and 1/1 is in Untrust&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1676"&gt;https://live.paloaltonetworks.com/docs/DOC-1676&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 21:28:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34949#M25655</guid>
      <dc:creator>BFCBahrain</dc:creator>
      <dc:date>2013-12-06T21:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Over IPSEC VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34950#M25656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I have gone tru once again .&lt;/P&gt;&lt;P&gt;Here i think I am using an IP that is not part of my Internal Address range .&lt;/P&gt;&lt;P&gt;So how do i route that IP ?Should I route the Nated IP address.&lt;/P&gt;&lt;P&gt;Can u pls guide.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 21:41:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34950#M25656</guid>
      <dc:creator>BFCBahrain</dc:creator>
      <dc:date>2013-12-06T21:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Over IPSEC VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34951#M25657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bahrain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;consider this when doing any nat.security policy,&lt;/P&gt;&lt;P&gt;the order of packet check is:&lt;/P&gt;&lt;P&gt;1) Destination Nat&lt;/P&gt;&lt;P&gt;2)routing table&lt;/P&gt;&lt;P&gt;3) Source nat&lt;/P&gt;&lt;P&gt;4) Security policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So when you are doing destination nat destination zone is decided based on route for pre-natted ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Dec 2013 16:01:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34951#M25657</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2013-12-07T16:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Over IPSEC VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34952#M25658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hyadavalli,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please give me more information ..&lt;/P&gt;&lt;P&gt;I gave my scenario ..can u pls help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Dec 2013 19:00:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34952#M25658</guid>
      <dc:creator>BFCBahrain</dc:creator>
      <dc:date>2013-12-08T19:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Over IPSEC VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34953#M25659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're using an IP address that does not exist on the PA-firewall as your natted-IP, then it means the firewall does not know how to route to this IP normally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try using a PBF policy to forward the traffic to your DMZ interface and/or next-hop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember that the firewall makes decisions based on zones. If the IP address is not on any interface on the firewall, then that IP address does not belong to any zones, hence, the firewall does not know what to do with the packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;tasonibare&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Dec 2013 07:12:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34953#M25659</guid>
      <dc:creator>tasonibare</dc:creator>
      <dc:date>2013-12-09T07:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Over IPSEC VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34954#M25660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in your case.&lt;/P&gt;&lt;P&gt;Check in routing table for the natted IP(Not dmz server IP) to verify what ineterface it points to and look for the zone the interface specified to and use that in destination zone for destination nat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Dec 2013 17:26:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn/m-p/34954#M25660</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2013-12-09T17:26:17Z</dc:date>
    </item>
  </channel>
</rss>

