<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policies security and NAT are bidireccional??? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policies-security-and-nat-are-bidireccional/m-p/40436#M29689</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;or i would need to create other rule from untrust to trust permitting SSH??? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Jul 2013 09:13:43 GMT</pubDate>
    <dc:creator>soporteseguridad</dc:creator>
    <dc:date>2013-07-24T09:13:43Z</dc:date>
    <item>
      <title>Policies security and NAT are bidireccional???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policies-security-and-nat-are-bidireccional/m-p/40435#M29688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;If there is a security policy applied from just "untrust to trust" permitting SSH traffic .. this rule will be bidirectional??? or i would need to create other rule from trus to trust permitting SSH??? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Its the same with NAT rules???&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 09:08:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policies-security-and-nat-are-bidireccional/m-p/40435#M29688</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-07-24T09:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Policies security and NAT are bidireccional???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policies-security-and-nat-are-bidireccional/m-p/40436#M29689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;or i would need to create other rule from untrust to trust permitting SSH??? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 09:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policies-security-and-nat-are-bidireccional/m-p/40436#M29689</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-07-24T09:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: Policies security and NAT are bidireccional???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policies-security-and-nat-are-bidireccional/m-p/40437#M29690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;From what I understand, you wanna&amp;nbsp; create a security rule from Untrust to Trust, so that people from the internet can access a server that is behind the firewall on the trust zone. If the users from the internet initiate a new ssh session to the firewall, then the firewall receives a SYN packet from the untrust to the trust zone. We need not write a new policy for the SYN-ACK from the trust to untrust to go out, and the firewall will match any the server to client traffic on ssh to the same "untrust to trust" rule that you created. So it depends upon who is initiating the session. If someone is initiating a new ssh connection from the trust zone, we would then require a policy from "trust to untrust" allowing ssh.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bear in mind that when we have an inbound connection from the internet ( untrust to trust), the NAT rules are written slightly differently, and you may wanna refer to the destination NAT configuration as mentioned under page 15 of&amp;nbsp; the NAT tech note, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;https://live.paloaltonetworks.com/docs/DOC-1517&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 13:43:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policies-security-and-nat-are-bidireccional/m-p/40437#M29690</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-07-24T13:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: Policies security and NAT are bidireccional???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policies-security-and-nat-are-bidireccional/m-p/40438#M29691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;first scenario&lt;/P&gt;&lt;P&gt;when&lt;/P&gt;&lt;P&gt;a client have to established session on a server with a source NAT to the aim of masking&amp;nbsp; the ip of the client or for routing purpose. you just need a static NAT without bidirectionnal option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;second scenario&lt;/P&gt;&lt;P&gt;if you create a static nat with the bidirectional option&amp;nbsp; and with a destination address declared.&lt;/P&gt;&lt;P&gt;you have the same behaviour, but its like you create another nat rule but a destination nat rule that allow the server to initiate a connection on your client of the first scenario&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that make sens? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 16:08:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policies-security-and-nat-are-bidireccional/m-p/40438#M29691</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-07-24T16:08:51Z</dc:date>
    </item>
  </channel>
</rss>

