<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple NAT and Private IP Addressing - Help Needed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-nat-and-private-ip-addressing-help-needed/m-p/44465#M32632</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gerald,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer following document page7, it confirms Martian packets are not supported.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="1628" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1628"&gt;Packet Flow in PAN-OS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following page confirms 169.254.0.1/32 belongs to martian IP.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://en.wikipedia.org/wiki/Martian_packet"&gt;Martian packet - Wikipedia, the free encyclopedia&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have more questions on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Jul 2013 23:21:46 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2013-07-11T23:21:46Z</dc:date>
    <item>
      <title>Multiple NAT and Private IP Addressing - Help Needed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-nat-and-private-ip-addressing-help-needed/m-p/44464#M32631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm relatively new to PA firewalls, so please forgive me if this is not explained well.&lt;/P&gt;&lt;P&gt;I have a PA-500 with PANOS 5.0.0. Im using three interfaces at present - e1/1 - internal network, e1/2 - Internet untrust, e1/3 internet untrust (private ip 169.254.0.1/32)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At present I have my rules configured and my NAT commands for my internet connection on e1/2 and this works fine. Both e1/1 and e1/2 are under a single virtual router, which also has an 0.0.0/0 route outbound. On this connection I have NAT inbound mapping ssl and other services to internal servers on the internal network (192.168.1.x) with no problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it happens that our email is delivered on the second internet connection, which is government-based, and uses a private addressing scheme.&lt;/P&gt;&lt;P&gt;I set up this connection as like the first, and added it to the default VR - cloned the nat policies and security policies, and changed the pointers. However no mail will come inbound. Furthermore, I cannot ping anything on this 169.254 range. Ive double-checked the NAT statements and all seem in order.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the first instance I thought that maybe my addresses were being translated by the first nat rule, so I added a nat translation only applicable to connections going to that network on 169.254.x.x, and ran the check NAT commands via the command-line. All checked out and the nat was being translated into the 169.254.x.x address on e1/3 correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im at a huge loss as to why the email is not being mapped to the mail server. every now and then in my logs I notice an allow from the mailserver on this network coming into my mailserver, but the connection is being listed as incomplete, and the logs only show up if the rule is set to log at end - no corresponding start of the connection can be seen.&lt;/P&gt;&lt;P&gt;I then tried a separate VR for this network but have not finished it yet as Ive no internal interface to add&amp;nbsp; - perhaps using a loopback might work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody have issues with NAT inbound from an external private ip address such as this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ger&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 22:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-nat-and-private-ip-addressing-help-needed/m-p/44464#M32631</guid>
      <dc:creator>Gerard.Gallagher</dc:creator>
      <dc:date>2013-07-11T22:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple NAT and Private IP Addressing - Help Needed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-nat-and-private-ip-addressing-help-needed/m-p/44465#M32632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gerald,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer following document page7, it confirms Martian packets are not supported.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="1628" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1628"&gt;Packet Flow in PAN-OS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following page confirms 169.254.0.1/32 belongs to martian IP.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://en.wikipedia.org/wiki/Martian_packet"&gt;Martian packet - Wikipedia, the free encyclopedia&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have more questions on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 23:21:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-nat-and-private-ip-addressing-help-needed/m-p/44465#M32632</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2013-07-11T23:21:46Z</dc:date>
    </item>
  </channel>
</rss>

