<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Source and Destination NAT in the same packet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38178#M27965</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For your example it should be like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Original Packet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source Zone: Internal&lt;/P&gt;&lt;P&gt;Destination Zone: Outside Zone&lt;/P&gt;&lt;P&gt;Destination IP: 194.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Translation:&lt;/P&gt;&lt;P&gt;Source:&lt;/P&gt;&lt;P&gt;Dynamic IP and Port&lt;/P&gt;&lt;P&gt;Interface: External Interface with 4.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination:&lt;/P&gt;&lt;P&gt;200.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security Policy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source Zone: Internal&lt;/P&gt;&lt;P&gt;Destination Zone: Outside Zone&lt;/P&gt;&lt;P&gt;Destination IP: 194.0.0.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Jan 2015 14:40:50 GMT</pubDate>
    <dc:creator>Wenar</dc:creator>
    <dc:date>2015-01-12T14:40:50Z</dc:date>
    <item>
      <title>Source and Destination NAT in the same packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38174#M27961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Source and Destination NAT in the same packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am required to configure source NAT and destination NAT for the same packet in a scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packets are flowing through the firewall from inside zone to outside zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per palo alto documentation i see for source NAT my zones for NAT rule:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source Zone : Inside&lt;/P&gt;&lt;P&gt;Destination zone :Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per palo alto documentation i see for destination NAT my zones for NAT rule:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source Zone : Inside&lt;/P&gt;&lt;P&gt;Destination zone :inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now my question is what will my source and destination zone be if i have done source NAT and destination NAT&amp;nbsp; in the same rule ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ARJUN DAS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2015 10:50:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38174#M27961</guid>
      <dc:creator>ArjunDAS</dc:creator>
      <dc:date>2015-01-12T10:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Source and Destination NAT in the same packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38175#M27962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's probably Source Zone: Inside and Destination Zone: Outside but I don't have enough information if this is needed for this configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which address do you want to use for DNAT? Is it one of you public IPs and in which zone is the address you want to DNAT?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2015 10:56:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38175#M27962</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2015-01-12T10:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Source and Destination NAT in the same packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38176#M27963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;lets say original source is 10.0.0.1/24&amp;nbsp; and destination is 194.0.0.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;source is to be translated to 4.0.0.1 (One of PA's public ip address, outside zone) and destination is to be translated to&amp;nbsp; 200.0.0.1 (Actual Destination servers IP in inetrnet)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;194.0.0.1 is in Outside zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;200.0.0.1 is in outside Zone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2015 11:16:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38176#M27963</guid>
      <dc:creator>ArjunDAS</dc:creator>
      <dc:date>2015-01-12T11:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: Source and Destination NAT in the same packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38177#M27964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should create the rule in the direction you expect tcp to initiate the connection.&amp;nbsp; The initiator system is the source zone and the destination system is the destination zone. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can see an example in the Understanding PA nat guide on page 24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;Understanding PAN-OS NAT&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2015 11:22:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38177#M27964</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-01-12T11:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: Source and Destination NAT in the same packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38178#M27965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For your example it should be like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Original Packet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source Zone: Internal&lt;/P&gt;&lt;P&gt;Destination Zone: Outside Zone&lt;/P&gt;&lt;P&gt;Destination IP: 194.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Translation:&lt;/P&gt;&lt;P&gt;Source:&lt;/P&gt;&lt;P&gt;Dynamic IP and Port&lt;/P&gt;&lt;P&gt;Interface: External Interface with 4.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination:&lt;/P&gt;&lt;P&gt;200.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security Policy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source Zone: Internal&lt;/P&gt;&lt;P&gt;Destination Zone: Outside Zone&lt;/P&gt;&lt;P&gt;Destination IP: 194.0.0.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2015 14:40:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38178#M27965</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2015-01-12T14:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: Source and Destination NAT in the same packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38179#M27966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arjun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the traffic is going from your internal zone to external (ex: internet) and you're natting both, your source zone will continue to be the internal zone. &lt;/P&gt;&lt;P&gt;For the destination zone, the firewall looks at the post NAT address and evaluates the interface where the packet should ultimately exit (by PBF or routing table). &lt;/P&gt;&lt;P&gt;Whatever zone this interface is in will be your destination zone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2015 20:49:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38179#M27966</guid>
      <dc:creator>rborda</dc:creator>
      <dc:date>2015-01-12T20:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Source and Destination NAT in the same packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38180#M27967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How can NAT destination zone be based on Post NAT address as NAT policies only are applicable to Pre NAT destination address ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jan 2015 09:24:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38180#M27967</guid>
      <dc:creator>ArjunDAS</dc:creator>
      <dc:date>2015-01-15T09:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: Source and Destination NAT in the same packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38181#M27968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The zone match for the nat rule is based on the original destination address.&amp;nbsp; But if that nat rule does a destination nat then the security policy rule that is needed to permit the traffic will be based on the destination nat address and not the original address zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2015-01-15 at 8.37.38 PM.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17795_Screen Shot 2015-01-15 at 8.37.38 PM.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1628"&gt;Packet Flow in PAN-OS&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jan 2015 01:39:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-and-destination-nat-in-the-same-packet/m-p/38181#M27968</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-01-16T01:39:49Z</dc:date>
    </item>
  </channel>
</rss>

