<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest Network Setup in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35283#M25920</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had a user error in the NAT &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt; Thanks for your thoughts!&amp;nbsp; Plus I ended up setting up a PBF rules as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Jul 2013 02:12:08 GMT</pubDate>
    <dc:creator>victorallen</dc:creator>
    <dc:date>2013-07-25T02:12:08Z</dc:date>
    <item>
      <title>Guest Network Setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35278#M25915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi - What is the best method to setup a guest L3 network in PanOS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UntrustA = Corporate&lt;/P&gt;&lt;P&gt;UntrustB= Guest Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wDMZ = Wireless DMZ for Guest Internet&lt;/P&gt;&lt;P&gt;trust = Corporate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Requirements =&lt;/P&gt;&lt;P&gt;1. wDMZ needs to get to a few specific IP's on UntrustA.&lt;/P&gt;&lt;P&gt;2. wDMZ needs to get to the Internet via UntrustB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Initially I was thinking of a second vRouter? OR is policy based forwarding the way to go?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Jul 2013 19:37:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35278#M25915</guid>
      <dc:creator>victorallen</dc:creator>
      <dc:date>2013-07-21T19:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Network Setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35279#M25916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the UntrustB is used to route the Guest traffic to internet then you can use a secondary VR that has wDMZ and UntrustB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need two routes in this VR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; A default route to internet via untrustB for guest users to get to internet&lt;/P&gt;&lt;P&gt;&amp;gt; A static route to get the corporate trust where the next hop would be type VR and value will be the primary VR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access from wDMZ to trust can be controlled using security polices than using routes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Jul 2013 21:13:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35279#M25916</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2013-07-21T21:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Network Setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35280#M25917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is what I had, but Internet was not routing out UntrustB.&amp;nbsp; DNS was routing fine to trust with policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if some of my issue is with UntrustB using DHCP for it's IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zone wGuest&lt;/P&gt;&lt;P&gt;&amp;gt; UntrustB&lt;/P&gt;&lt;P&gt;&amp;gt; wDMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static Route 0.0.0.0/0 UntrustB&lt;/P&gt;&lt;P&gt;Static Route (trust) x.x.x.x/24 Next - VR (trust)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also had policy..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wDMZ to UntrustB allow everything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Jul 2013 21:36:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35280#M25917</guid>
      <dc:creator>victorallen</dc:creator>
      <dc:date>2013-07-21T21:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Network Setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35281#M25918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a NAT policy configured ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 13:21:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35281#M25918</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2013-07-24T13:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Network Setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35282#M25919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with nat to confirme it &lt;/P&gt;&lt;P&gt;activate log at start sesion on your policy rule which have allow your traffic and&lt;/P&gt;&lt;P&gt;go to traffic log in monitor tab&amp;nbsp; and check if you see incomplete application.&lt;/P&gt;&lt;P&gt;if yes that mean you send something but with no retourn back to you.&lt;/P&gt;&lt;P&gt;resolv that by source nat policy which change the client ip to the ip of your untrust interface (the ip gave by dhcp) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 16:32:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35282#M25919</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-07-24T16:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Network Setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35283#M25920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had a user error in the NAT &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt; Thanks for your thoughts!&amp;nbsp; Plus I ended up setting up a PBF rules as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jul 2013 02:12:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guest-network-setup/m-p/35283#M25920</guid>
      <dc:creator>victorallen</dc:creator>
      <dc:date>2013-07-25T02:12:08Z</dc:date>
    </item>
  </channel>
</rss>

