<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot browse nat webpage internally in lan in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-browse-nat-webpage-internally-in-lan/m-p/39990#M29321</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the clients and the servers are on the same LAN then the response from the server is likely going directly to the client and not back through the firewall.&amp;nbsp; The client is receiving a response packet with the internal address instead of the external one so it rejects the packet as unexpected.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To fix this scenario you can set up a Source-NAT + Destination-NAT rule from the client subnet to the servers so the return traffic is forced back to the firewall and correctly processed for NAT and security before it gets to the client. This concept is known as a U-Turn NAT Rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Jul 2011 05:42:56 GMT</pubDate>
    <dc:creator>kbrazil</dc:creator>
    <dc:date>2011-07-12T05:42:56Z</dc:date>
    <item>
      <title>Cannot browse nat webpage internally in lan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-browse-nat-webpage-internally-in-lan/m-p/39989#M29320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have some internet facing servers who has NAT public address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Externally we can access the public address of the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Internally on our LAN, we cannot access the public address of the server, it timed out. However the appliance monitor tab shows accept, nothing was denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The policy rules i set was&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any to Any - Server_public_address - Web browsing allowed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone knows what could be causing this issue ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 04:44:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-browse-nat-webpage-internally-in-lan/m-p/39989#M29320</guid>
      <dc:creator>mmxong</dc:creator>
      <dc:date>2011-07-12T04:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot browse nat webpage internally in lan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-browse-nat-webpage-internally-in-lan/m-p/39990#M29321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the clients and the servers are on the same LAN then the response from the server is likely going directly to the client and not back through the firewall.&amp;nbsp; The client is receiving a response packet with the internal address instead of the external one so it rejects the packet as unexpected.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To fix this scenario you can set up a Source-NAT + Destination-NAT rule from the client subnet to the servers so the return traffic is forced back to the firewall and correctly processed for NAT and security before it gets to the client. This concept is known as a U-Turn NAT Rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 05:42:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-browse-nat-webpage-internally-in-lan/m-p/39990#M29321</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-07-12T05:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot browse nat webpage internally in lan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-browse-nat-webpage-internally-in-lan/m-p/39991#M29322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just posted a somewhat similar issue.&amp;nbsp; Explicitly allowing the traffic (even though the logs were not showing anything was blocked) resolved the problem.&amp;nbsp; My post asked why this behavior is occuring.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 18:05:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-browse-nat-webpage-internally-in-lan/m-p/39991#M29322</guid>
      <dc:creator>bhelman</dc:creator>
      <dc:date>2011-07-12T18:05:44Z</dc:date>
    </item>
  </channel>
</rss>

