<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic static nat + intrazone u-turn and interzone u-turn at same time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/static-nat-intrazone-u-turn-and-interzone-u-turn-at-same-time/m-p/38333#M28083</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm currently having problems on PAN OS 5.0.1 replicating a standard Screenos MIP configuration. Whereby static nat and interzone/intrazone u-turn nat are all active at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have multiple zones (5) all of the hosts inside each need to be able to access DMZ servers by their NATd public ip address (multiple dmz zones). Also unfortunately hosts inside the DMZ's sometimes want to talk back to themselves using their public ip address instead of their private.. Terrible I know..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also when the DMZ servers talk to the internet they need to appear as their static natd public address.. when they talk to the internal (inside) network they appear as their standard private address..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is a screenshot of the NAT configuration for 1 DMZ server..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The intrazone and interzone u-turn nating only work when the SNAT (static source translation) is not enabled..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know we could be using split-dns.. and also this current design is begging for a re-architecture.. but we currently need to maintain status quo functionality for this firewall transition..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Mar 2013 01:37:55 GMT</pubDate>
    <dc:creator>CMG</dc:creator>
    <dc:date>2013-03-26T01:37:55Z</dc:date>
    <item>
      <title>static nat + intrazone u-turn and interzone u-turn at same time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-nat-intrazone-u-turn-and-interzone-u-turn-at-same-time/m-p/38333#M28083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm currently having problems on PAN OS 5.0.1 replicating a standard Screenos MIP configuration. Whereby static nat and interzone/intrazone u-turn nat are all active at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have multiple zones (5) all of the hosts inside each need to be able to access DMZ servers by their NATd public ip address (multiple dmz zones). Also unfortunately hosts inside the DMZ's sometimes want to talk back to themselves using their public ip address instead of their private.. Terrible I know..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also when the DMZ servers talk to the internet they need to appear as their static natd public address.. when they talk to the internal (inside) network they appear as their standard private address..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is a screenshot of the NAT configuration for 1 DMZ server..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The intrazone and interzone u-turn nating only work when the SNAT (static source translation) is not enabled..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know we could be using split-dns.. and also this current design is begging for a re-architecture.. but we currently need to maintain status quo functionality for this firewall transition..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 01:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-nat-intrazone-u-turn-and-interzone-u-turn-at-same-time/m-p/38333#M28083</guid>
      <dc:creator>CMG</dc:creator>
      <dc:date>2013-03-26T01:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: static nat + intrazone u-turn and interzone u-turn at same time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-nat-intrazone-u-turn-and-interzone-u-turn-at-same-time/m-p/38334#M28084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So what is the problem with enable SNAT ?&lt;/P&gt;&lt;P&gt;Could you please clarify what is not working ? Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 10:35:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-nat-intrazone-u-turn-and-interzone-u-turn-at-same-time/m-p/38334#M28084</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-03-26T10:35:13Z</dc:date>
    </item>
  </channel>
</rss>

