<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Help - Reaching DMZ Server via NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40896#M30053</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kunal,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for the prompt reply.&amp;nbsp; In the midst of providing examples of my configuration I left out the 10.10.100.10 for the destination translation, but for the actual policy, it is there.&amp;nbsp; In regards to the security policy, I tried adding the destination IP, although keeping the tab to "any" should of worked as well.&amp;nbsp; Neither option worked.&amp;nbsp; I appreciate the document you provided, I've referenced this particular document a few times on trying to troubleshoot this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To add to my configuration information above, I have a route for 10.10.100.0/24 with the interface set to e1/3 and next hope value 10.10.100.5 (Gateway on the PA).&amp;nbsp; I do not have a route for the public IP subnet however.&amp;nbsp; Is this needed?&amp;nbsp; Again, I'm not seeing any internet traffic hit the firewall for destination address 1.1.1.171.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Sep 2013 17:33:24 GMT</pubDate>
    <dc:creator>jmeyer1</dc:creator>
    <dc:date>2013-09-20T17:33:24Z</dc:date>
    <item>
      <title>NAT Help - Reaching DMZ Server via NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40893#M30050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having an issue setting up my DMZ test environment.&amp;nbsp; My set up is basic and is as follows (IP information is an example) --&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;e1/1 - Internet (1.1.1.160/28 - ISP assigned)&lt;/LI&gt;&lt;LI&gt;e1/2 - Internal (10.10.10.0/24)&lt;/LI&gt;&lt;LI&gt;e1/3 - DMZ (10.10.100.0/24)&lt;/LI&gt;&lt;LI&gt;DMZ Web Server (Internal IP 10.10.100.10/24 with NAT rule for external IP mapping of 1.1.1.171)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've set up a NAT policy as seen below --&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PA_NAT_Policy.PNG.png" class="jive-image" height="43" src="https://live.paloaltonetworks.com/legacyfs/online/8503_PA_NAT_Policy.PNG.png" style="width: 1211.818181818182px; height: 43px;" width="1212" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've set up the security policies as seen below --&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PA_Security_Policy.PNG.png" class="jive-image" height="104" src="https://live.paloaltonetworks.com/legacyfs/online/8504_PA_Security_Policy.PNG.png" style="width: 1216.6037735849056px; height: 104px;" width="1217" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internally, I can ping 1.1.1.171 and access my web server via that IP, however when I try and attempt to access the IP from the internet (https), I'm unable to hit the server and I do not see traffic hitting the firewall.&amp;nbsp; I've attempted to create a loopback to give the IP an endpoint as seen in a tutorial within this site, however that did not work either. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it appear that I am missing something or is my configuration incorrect?&amp;nbsp; I'm sure I'm a step or two away from getting this to work, however have been trying almost everything I can think of with little to no avail.&amp;nbsp; I would greatly appreciate any advice or help anyone can provide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 16:40:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40893#M30050</guid>
      <dc:creator>jmeyer1</dc:creator>
      <dc:date>2013-09-20T16:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Help - Reaching DMZ Server via NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40894#M30051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your D-NAT rule:&lt;/P&gt;&lt;P&gt;Source Zone : TW Internet&lt;/P&gt;&lt;P&gt;Destination Zone should also be : TW Internet&lt;/P&gt;&lt;P&gt;Destination Address:1.1.1.71&lt;/P&gt;&lt;P&gt;Destination Translation should be : &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;10.10.100.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your security rule:&lt;/P&gt;&lt;P&gt;Source Zone : Tw Internet&lt;/P&gt;&lt;P&gt;Destination Zone : DMA zone where the server actually lies&lt;/P&gt;&lt;P&gt;Destination IP :&amp;nbsp; &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;1.1.1.171&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if it worked for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 16:45:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40894#M30051</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-09-20T16:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Help - Reaching DMZ Server via NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40895#M30052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can also refer to page -16 of the following document. It explains you with an example of how DMZ servers are access from the outside.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;https://live.paloaltonetworks.com/docs/DOC-1517&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 16:47:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40895#M30052</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-09-20T16:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Help - Reaching DMZ Server via NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40896#M30053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kunal,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for the prompt reply.&amp;nbsp; In the midst of providing examples of my configuration I left out the 10.10.100.10 for the destination translation, but for the actual policy, it is there.&amp;nbsp; In regards to the security policy, I tried adding the destination IP, although keeping the tab to "any" should of worked as well.&amp;nbsp; Neither option worked.&amp;nbsp; I appreciate the document you provided, I've referenced this particular document a few times on trying to troubleshoot this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To add to my configuration information above, I have a route for 10.10.100.0/24 with the interface set to e1/3 and next hope value 10.10.100.5 (Gateway on the PA).&amp;nbsp; I do not have a route for the public IP subnet however.&amp;nbsp; Is this needed?&amp;nbsp; Again, I'm not seeing any internet traffic hit the firewall for destination address 1.1.1.171.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 17:33:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40896#M30053</guid>
      <dc:creator>jmeyer1</dc:creator>
      <dc:date>2013-09-20T17:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Help - Reaching DMZ Server via NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40897#M30054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only route you require is on upstream router. The upstream router should know that if a packet comes in destined for &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;1.1.1.171, it should forward it to PAN's 1/1, since &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;1.1.1.171&lt;/SPAN&gt; comes under &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;1.1.1.160/28&lt;/SPAN&gt;'s umbrella. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I would look for any sessions/traffic logs on the PAN sourcing from that outside client hitting &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;1.1.1.171&lt;/SPAN&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;For example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Server (&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;10.10.100.10&lt;/SPAN&gt;)&amp;nbsp; ---- PAN ---- ISP-----&amp;nbsp; PC (1.1.1.1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&amp;gt; show session all filter source &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;1.1.1.1&lt;/SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;If you don't see any sessions from 1.1.1.1, its very likely that there could be some routing issues on the ISP/upstream side.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Also, you can verify through your traffic logs. You can use the following filter : ( addr.src in 1.1.1.1 ) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;One thing I noticed now in your first comment is that you said - "&lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Internally, I can ping 1.1.1.171&lt;/SPAN&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;"..... Does that mean even the local &lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;LAN&lt;/SPAN&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; subnets are accessing that web-server using public ip address? If that is the case, we are dealing with a U-Turn NAT situation here!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Kunal Adak&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 19:48:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40897#M30054</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-09-20T19:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Help - Reaching DMZ Server via NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40898#M30055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you try to reach your webserver from inside ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to use u-turn nat then&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1678" title="https://live.paloaltonetworks.com/docs/DOC-1678"&gt;https://live.paloaltonetworks.com/docs/DOC-1678&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Sep 2013 18:39:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-help-reaching-dmz-server-via-nat/m-p/40898#M30055</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-09-21T18:39:03Z</dc:date>
    </item>
  </channel>
</rss>

