<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Destination NAT with different subnet of Outside interface. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35678#M26203</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;panos, I have configured upstream router with static routes for secondary subnet towards outside interface of PA FW.&lt;/P&gt;&lt;P&gt;Apart from this Destination Nat is configured with Security Policies to allow the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you please let us know how to troubleshoot? still the servers are not accessible from internet form secondary subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Parvez&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Jan 2014 09:00:31 GMT</pubDate>
    <dc:creator>ParvezAhmad</dc:creator>
    <dc:date>2014-01-08T09:00:31Z</dc:date>
    <item>
      <title>Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35671#M26196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside interface of Palo Alto firewall is configured with aaa.bbb.ccc.ddd /30 subnet.&lt;/P&gt;&lt;P&gt;I have some servers in DMZ those need to be accessed via internet with IP address(es)/subnet ZZZ.XXX.YYY.VVV/24.&lt;/P&gt;&lt;P&gt;I have configured Destination Nat( including Security Policy) for these servers with the IP addresses as mentioned above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know how this can work? Do we need to add static route on upstream router for new subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 07:39:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35671#M26196</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-05T07:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35672#M26197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so you mean zzz.xxx.yyy.vvv/24 is public ip subnet also ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 08:39:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35672#M26197</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-01-05T08:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35673#M26198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, zzz.xxx.yyy.vvv/24 is public subnet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 08:44:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35673#M26198</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-05T08:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35674#M26199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok so when accessing this /24 subnet from internet that traffic should come to aaa.bbb.ccc.ddd /30's interface(upstream should route that traffic)&lt;/P&gt;&lt;P&gt;you can add this /24 subnet to the outside interface as second.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 09:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35674#M26199</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-01-05T09:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35675#M26200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;panos, would please let me know how we can add secondary IP address to Outside interface of FW?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 11:15:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35675#M26200</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-05T11:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35676#M26201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="layer3.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10604_layer3.png" style="width: 620px; height: 370px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 11:26:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35676#M26201</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-01-05T11:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35677#M26202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;panos, Thanks a lot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 11:30:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35677#M26202</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-05T11:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35678#M26203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;panos, I have configured upstream router with static routes for secondary subnet towards outside interface of PA FW.&lt;/P&gt;&lt;P&gt;Apart from this Destination Nat is configured with Security Policies to allow the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you please let us know how to troubleshoot? still the servers are not accessible from internet form secondary subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Parvez&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 09:00:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35678#M26203</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-08T09:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35679#M26204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you may use packet capture to troubleshoot while accessing from outside to that secondary subnet&lt;/P&gt;&lt;P&gt;so that we'll see if traffic comes(and we drop)&amp;nbsp; or not&lt;/P&gt;&lt;P&gt;if not so problem is related to upstream&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 09:44:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35679#M26204</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-01-08T09:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35680#M26205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;be careful about the rule &lt;/P&gt;&lt;P&gt;you have to create the rule from internet to DMZ base on the &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;ZZZ.XXX.YYY.VVV/24&lt;/SPAN&gt; ip and not on the NAT ip.&lt;/P&gt;&lt;P&gt;if you have a rule like deny all at the bottom of the rule list, you will see if a deny action is present in the traffic log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regard's &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 11:04:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35680#M26205</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-01-08T11:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35681#M26206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep that in mind :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="nat.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10685_nat.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 12:47:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35681#M26206</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-01-08T12:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35682#M26207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gregoux, If I will put deny all at the bottom, Do we need to allow separate rules outside to outside, DMZ to DMZ and Inside to inside for all traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 12:54:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35682#M26207</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-08T12:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35683#M26208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot. I created the rules as mentioned in this snapshot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 12:58:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35683#M26208</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-08T12:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT with different subnet of Outside interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35684#M26209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot . The migration was successful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 12:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-with-different-subnet-of-outside-interface/m-p/35684#M26209</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-23T12:43:39Z</dc:date>
    </item>
  </channel>
</rss>

