<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Public IP's and DMZ in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/public-ip-s-and-dmz/m-p/44648#M32765</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am currently setting up a DMZ using a class C address range provided by my ISP. So far I have an untagged interface built connected to a switch and a VR built. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the subnet 10.10.10.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set interface G1/2 with address 10.10.10.1/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a VR with a route 10.10.10.0/24 destination int G1/2 next hop address 10.10.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a laptop with an address 10.10.10.10 I do not want this to NAT but use the address I assigned to it out of the class C range provided by my ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far I can ping my .1 gateway but haven't been able to get any farther.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Oct 2012 18:07:45 GMT</pubDate>
    <dc:creator>mgross</dc:creator>
    <dc:date>2012-10-16T18:07:45Z</dc:date>
    <item>
      <title>Public IP's and DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/public-ip-s-and-dmz/m-p/44648#M32765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am currently setting up a DMZ using a class C address range provided by my ISP. So far I have an untagged interface built connected to a switch and a VR built. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the subnet 10.10.10.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set interface G1/2 with address 10.10.10.1/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a VR with a route 10.10.10.0/24 destination int G1/2 next hop address 10.10.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a laptop with an address 10.10.10.10 I do not want this to NAT but use the address I assigned to it out of the class C range provided by my ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far I can ping my .1 gateway but haven't been able to get any farther.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 18:07:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/public-ip-s-and-dmz/m-p/44648#M32765</guid>
      <dc:creator>mgross</dc:creator>
      <dc:date>2012-10-16T18:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Public IP's and DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/public-ip-s-and-dmz/m-p/44649#M32766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After further research I have yet to resolve the issue but was wondering if I would have to build any NAT policy to accommodate this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 20:07:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/public-ip-s-and-dmz/m-p/44649#M32766</guid>
      <dc:creator>mgross</dc:creator>
      <dc:date>2012-10-16T20:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Public IP's and DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/public-ip-s-and-dmz/m-p/44650#M32767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since interface ethernet1/2 is directly connected to the 10.10.10.0/24 subnet with an address of 10.10.10.1 specifying a static route for this network in your virtual router is superfluous and therefore should not be necessary.&lt;/P&gt;&lt;P&gt;You will need to configure NAT to allow the 10.10.10.10 host outbound access to public IP space.&amp;nbsp; The following tech note covers PAN-OS NAT examples in detail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;https://live.paloaltonetworks.com/docs/DOC-1517&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 00:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/public-ip-s-and-dmz/m-p/44650#M32767</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2012-10-17T00:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Public IP's and DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/public-ip-s-and-dmz/m-p/44651#M32768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What you normally do (at least by my experience) is that you setup whats called a linknet between you and your ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This linknet is normally a /30 network such as 10.0.0.1 is ISP and you are 10.0.0.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ISP will then route 10.10.10.0/24 with nexthop 10.0.0.2 (your equipment).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While you have a default route (0.0.0.0/0) pointing towards ISP at 10.0.0.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This gives that your WAN interface will have 10.0.0.2/30 as ip adress, your (public) DMZ interface will have 10.10.10.1/24 (this will be the defgw for the DMZ-servers) and your (private) LAN interface will have 192.168.0.1/24 (or whatever floats your boat &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this 10.10.10.0/24 is actually a public ip range then you wont need any nating in your PA for traffic going WAN &amp;lt;-&amp;gt; DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you will need SNAT (Source NAT) for traffic going LAN -&amp;gt; WAN (mot not necessary for LAN &amp;lt;-&amp;gt; DMZ).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you for some reason needs to allow WAN -&amp;gt; LAN you do this with preferly portforwarding using DNAT (Destination NAT) - depending on if its a single port you need to allow or a full ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A workaround for above in case your ISP refuse to setup a linknet is to use the PA in VWIRE mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setup eth1 as VWIRE towards ISP and eth2 VWIRE towards DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then setup eth3 as regular L3 interface towards ISP and eth4 as L3 towards LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way the PA will "switch" traffic between ISP and DMZ while on eth3 it will be a single host on the same network (to SNAT the LAN-clients).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 09:25:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/public-ip-s-and-dmz/m-p/44651#M32768</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-17T09:25:43Z</dc:date>
    </item>
  </channel>
</rss>

