<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with NAT rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-nat-rules/m-p/42832#M31437</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Task is simple, give access to 3 IP from Internet to camera on non-standart ports. Ports and&amp;nbsp; local IP are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 192.168.220.251:554 -&amp;gt; x.x.x.x:554&lt;/P&gt;&lt;P&gt; 192.168.220.251:80 -&amp;gt; x.x.x.x:8881&lt;/P&gt;&lt;P&gt; 192.168.220.251:8554-8557 -&amp;gt; x.x.x.x:8554-8557&lt;/P&gt;&lt;P&gt;where x.x.x.x is one of IP belongings for my PA and is used for NAT from this zone to untrust.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created security rules:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-05-20_174032.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13574_2014-05-20_174032.png" style="width: 620px; height: 33px;" /&gt;&lt;/P&gt;&lt;P&gt;and NAT rules:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-05-20_174055.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13575_2014-05-20_174055.png" style="width: 620px; height: 67px;" /&gt;&lt;/P&gt;&lt;P&gt;but it doesn't working. For first step I'd like to test port 80 redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I try to change something. When I remove 8881tcp from security number 14 I'm able to open web page of IP camera using x.x.x.x:80.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please tell me where is my mistake?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 May 2014 19:05:33 GMT</pubDate>
    <dc:creator>_slv_</dc:creator>
    <dc:date>2014-05-20T19:05:33Z</dc:date>
    <item>
      <title>Problem with NAT rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-nat-rules/m-p/42832#M31437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Task is simple, give access to 3 IP from Internet to camera on non-standart ports. Ports and&amp;nbsp; local IP are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 192.168.220.251:554 -&amp;gt; x.x.x.x:554&lt;/P&gt;&lt;P&gt; 192.168.220.251:80 -&amp;gt; x.x.x.x:8881&lt;/P&gt;&lt;P&gt; 192.168.220.251:8554-8557 -&amp;gt; x.x.x.x:8554-8557&lt;/P&gt;&lt;P&gt;where x.x.x.x is one of IP belongings for my PA and is used for NAT from this zone to untrust.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created security rules:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-05-20_174032.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13574_2014-05-20_174032.png" style="width: 620px; height: 33px;" /&gt;&lt;/P&gt;&lt;P&gt;and NAT rules:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-05-20_174055.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13575_2014-05-20_174055.png" style="width: 620px; height: 67px;" /&gt;&lt;/P&gt;&lt;P&gt;but it doesn't working. For first step I'd like to test port 80 redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I try to change something. When I remove 8881tcp from security number 14 I'm able to open web page of IP camera using x.x.x.x:80.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please tell me where is my mistake?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2014 19:05:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-nat-rules/m-p/42832#M31437</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-05-20T19:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAT rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-nat-rules/m-p/42833#M31438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When creating a Inbound NAT make sure that you source address is the address of where the traffic is coming from. In this case of the camera.&lt;/P&gt;&lt;P&gt;Your destination address is the public interface IP on the palo alto firewall.&lt;/P&gt;&lt;P&gt;Since you have them hidden and not described in the above question not sure if that is what you are doing. Please confirm that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following document from page 15 explains different destination NAT scenarios.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;Understanding PAN-OS NAT&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let us know if this helps.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2014 19:31:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-nat-rules/m-p/42833#M31438</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-05-20T19:31:25Z</dc:date>
    </item>
  </channel>
</rss>

