<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: bi-direction NAT question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4618#M3389</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right so in this configuration, if 10.100.10.50 is going to anything in the (address group) it will get translated to 209.165.241.88.&amp;nbsp; And then ANYTHING hitting 209.165.241.88 from the outside will get translated to 10.100.10.50 according to my lab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I wanted was for the source of the inbound to be limited to only the (address group). To accomplish this I need a second destination NAT for it to work how I want. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Aug 2012 22:23:11 GMT</pubDate>
    <dc:creator>rob.burgoyne</dc:creator>
    <dc:date>2012-08-10T22:23:11Z</dc:date>
    <item>
      <title>bi-direction NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4613#M3384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the following rule in the firewall and was wondering if I needed to create a second rule for the other direction or if the bi-directional option will take care of it for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example&lt;/P&gt;&lt;P&gt;source address :10.100.10.50&amp;nbsp;&amp;nbsp; &amp;gt; destination address: FTPSERVERSGROUP&amp;nbsp; &amp;gt; Source Translation: static-ip 209.165.241.88&amp;nbsp; bi-directional &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically if 10.100.10.50 is going to any of the IPs in the FTPSERVERSGROUP I want it to get translated to 209.165.241.88, and I also want the flip of anything coming from FTPSERVERSGROUP to 209.165.241.88 get translated to 192.168.1.10. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just want to make sure I don't need a source translation and then a destination translation or if the bi-directional option will take care of it.... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 17:56:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4613#M3384</guid>
      <dc:creator>rob.burgoyne</dc:creator>
      <dc:date>2012-08-09T17:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: bi-direction NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4614#M3385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone tried this before?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2012 18:21:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4614#M3385</guid>
      <dc:creator>rob.burgoyne</dc:creator>
      <dc:date>2012-08-10T18:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: bi-direction NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4615#M3386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;We have a few bi-directional NAT rules in place.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;i.e. dmz &amp;gt; untrust &amp;gt; src-address (private-ip) &amp;gt;&amp;nbsp; src-translation static, (public-ip), bi-directional&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;This works well for us for incoming and outgoing traffic for our mail and web server.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;You just need to have the appropriate security rules in place to allow the traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2012 18:47:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4615#M3386</guid>
      <dc:creator>panwmod</dc:creator>
      <dc:date>2012-08-10T18:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: bi-direction NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4616#M3387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok so I was able to Lab this up and these are the results. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Original Packet &lt;/P&gt;&lt;P&gt;Source: 192.168.1.254 (INSIDE)&lt;/P&gt;&lt;P&gt;Destination: SERVER GROUP (OUTSIDE)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source Static Translation&lt;/P&gt;&lt;P&gt;172.16.1.1 (OUTSIDE)&lt;/P&gt;&lt;P&gt;Bi-Directional - Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok so on workstation 192.168.1.254 I am able to ping all of the IP's in the server group and NAT looks to be working correctly outbound. If I try to ping anything other than the server group it fails as expected (since it doesn't match destination).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However I am then able to ping (192.168.1.254) from anything via (172.16.1.1) inbound. I was hoping that it would only NAT it if the source was from the server group, which is not the case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it looks as though I have to disable bi-directional and manually create a destination NAT sourced from SERVER GROUP destination 172.16.1.1 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2012 18:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4616#M3387</guid>
      <dc:creator>rob.burgoyne</dc:creator>
      <dc:date>2012-08-10T18:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: bi-direction NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4617#M3388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, I assume your rule looks more like this:&lt;/P&gt;&lt;P&gt;src-zone=dmz &amp;gt; dstzone=untrust &amp;gt; src-address=(10.100.10.50) &amp;gt; dst-address=(address-group) &amp;gt; src-translation=static-ip, (209.165.241.88), bi-directional &amp;gt; dst-translation=none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is still bidirectional. A destination address without destination will only 'restrict' the matching traffic.&lt;/P&gt;&lt;P&gt;For 'outgoing' traffic if the destination needs to match the address-group and for 'incoming' traffic the source has to match the address-group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in minde that the positioning of the rule also determines if it will be matched or not. The NAT rule base is also 'read' top to bottom.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2012 20:27:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4617#M3388</guid>
      <dc:creator>panwmod</dc:creator>
      <dc:date>2012-08-10T20:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: bi-direction NAT question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4618#M3389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right so in this configuration, if 10.100.10.50 is going to anything in the (address group) it will get translated to 209.165.241.88.&amp;nbsp; And then ANYTHING hitting 209.165.241.88 from the outside will get translated to 10.100.10.50 according to my lab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I wanted was for the source of the inbound to be limited to only the (address group). To accomplish this I need a second destination NAT for it to work how I want. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2012 22:23:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bi-direction-nat-question/m-p/4618#M3389</guid>
      <dc:creator>rob.burgoyne</dc:creator>
      <dc:date>2012-08-10T22:23:11Z</dc:date>
    </item>
  </channel>
</rss>

