<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question On NAT Configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35821#M26331</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried this, creating a Dynamic IP type NAT for the Meraki Device (for outbound service UDP 9350), while maintaining the Dynamic IP and Port type NAT for the rest of my traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But once I committed the configuration, the firewall stopped passing traffic altogether. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I substituted the Dynamic IP NAT type, with a Static NAT and the same criteria, but the same issue continued. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 30 Nov 2014 20:08:02 GMT</pubDate>
    <dc:creator>MadanSudhindra</dc:creator>
    <dc:date>2014-11-30T20:08:02Z</dc:date>
    <item>
      <title>Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35813#M26323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PA-200 at home, sitting behind a Comcast modem, that hands out&amp;nbsp; a single DHCP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have a Meraki Z1 VPN device associated with work, that I have behind the PA-200. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Meraki requires that the source port not be translated, when attempting to contact the Meraki cloud concentrator. &lt;/P&gt;&lt;P&gt;The Defualy Source NAT gives me an error like this on the Meraki service end - "NAT Type: Unfriendly". Here is Meraki's troubleshooting document explaining the issue - &lt;A href="https://kb.meraki.com/knowledge_base/troubleshooting-automatic-nat-traversal-registration" title="https://kb.meraki.com/knowledge_base/troubleshooting-automatic-nat-traversal-registration"&gt;Troubleshooting Automatic NAT traversal VPN Registration - Cisco Meraki KB - Meraki Dashboard&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any pointers on how I can successfully configure the PA-200 to pass the Meraki traffic without changing the source port, while allowing all my other home internet traffic to go through ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Madan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Nov 2014 06:47:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35813#M26323</guid>
      <dc:creator>MadanSudhindra</dc:creator>
      <dc:date>2014-11-27T06:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35814#M26324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have meraki AP and I didnt experience any problem with NAT. &lt;/P&gt;&lt;P&gt;Please create security policy from IP_of_Meraki to Untrust with aplication any, service any that will allow traffic and after few hours/minuts You can go to traffic and filter traffic from this rule to see what apllication is needed.&lt;/P&gt;&lt;P&gt;In my scenario it is:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-11-27_082350.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17073_2014-11-27_082350.png" style="height: 50px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Nov 2014 07:25:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35814#M26324</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-11-27T07:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35815#M26325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12.222222328186px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1413" data-externalid="" data-presence="null" data-userid="29335" data-username="MadanSudhindra" href="https://live.paloaltonetworks.com/people/MadanSudhindra" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;MadanSudhindra&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may configure a separate NAT policy for VPN peer address, without port translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For example:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;DHCP address on the PAN interface= 1.1.1.1 (&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;untrust&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;VPN &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;peer&lt;/SPAN&gt; public address =2&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a NAT policy only for &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13.3333339691162px;"&gt; Meraki traffic and place this on the top of the policy table.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NAT-vpn.JPG" class="image-0 jive-image" height="238" src="https://live.paloaltonetworks.com/legacyfs/online/17075_NAT-vpn.JPG" style="height: 237.561290322581px; width: 456px;" width="456" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NAT-vpn-1.JPG" class="image-1 jive-image" height="300" src="https://live.paloaltonetworks.com/legacyfs/online/17076_NAT-vpn-1.JPG" style="height: 299.690322580645px; width: 474px;" width="473" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Nov 2014 08:15:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35815#M26325</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-27T08:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35816#M26326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to use Dynamic IP type NAT, I have to specify a definite address. In my case, the address is handed out by Comcast's DHCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried defining a static with an address as a FQDN derived address, but NAT cannot use a FQDN type address when defining a static or a Dynamic IP NAT. It has a be a pre-defined value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Nov 2014 17:58:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35816#M26326</guid>
      <dc:creator>MadanSudhindra</dc:creator>
      <dc:date>2014-11-27T17:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35817#M26327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/13469"&gt;slv&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have such a rule defined. It basically allows my home network IP address range to get out to the internet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Nov 2014 17:59:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35817#M26327</guid>
      <dc:creator>MadanSudhindra</dc:creator>
      <dc:date>2014-11-27T17:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35818#M26328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12.222222328186px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1413" data-externalid="" data-presence="null" data-userid="29335" data-username="MadanSudhindra" href="https://live.paloaltonetworks.com/people/MadanSudhindra" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;MadanSudhindra&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't use FQDN name, use the address assigned by the DHCP server in a static form. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Nov 2014 19:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35818#M26328</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-27T19:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35819#M26329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But, that would be "dynamic IP and port" not "dynamic IP only"...? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Nov 2014 20:01:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35819#M26329</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-27T20:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35820#M26330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello @HULK,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is something I can try. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll try it and let you know. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Madan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Nov 2014 22:34:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35820#M26330</guid>
      <dc:creator>MadanSudhindra</dc:creator>
      <dc:date>2014-11-27T22:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35821#M26331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried this, creating a Dynamic IP type NAT for the Meraki Device (for outbound service UDP 9350), while maintaining the Dynamic IP and Port type NAT for the rest of my traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But once I committed the configuration, the firewall stopped passing traffic altogether. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I substituted the Dynamic IP NAT type, with a Static NAT and the same criteria, but the same issue continued. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Nov 2014 20:08:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35821#M26331</guid>
      <dc:creator>MadanSudhindra</dc:creator>
      <dc:date>2014-11-30T20:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35822#M26332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Madan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you mention specific source and destination IP address &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;on&lt;/SPAN&gt; that new NAT policy...? Ideally, this NAT policy should not impact your other traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Dec 2014 06:22:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35822#M26332</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-12-01T06:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Question On NAT Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35823#M26333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a screenshot of my NAT Policy -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NAT.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17115_NAT.jpg" style="height: 80px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had to edit the NAT policy to all apply to traffic from the outside interface of the Meraki, as applying this to only port UDP 9350, will make everything appear OK on the Meraki portal, but wont create the VPN tunnels.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Dec 2014 06:39:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-nat-configuration/m-p/35823#M26333</guid>
      <dc:creator>MadanSudhindra</dc:creator>
      <dc:date>2014-12-03T06:39:27Z</dc:date>
    </item>
  </channel>
</rss>

