<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone Assignment in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-assignment/m-p/46193#M33946</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jeff,&lt;/P&gt;&lt;P&gt;For NAT rules, zone matching is based on ingress interface and egress interface after PBF policy or route table lookup.&lt;BR /&gt;Zone matching for Security rules is a post nat process; so a second lookup will occur after applying destination NAT rule (if there was a Nat policy match).&lt;BR /&gt;on the other side, for ip matching, in security policy, you always have to keep pre-NAT IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using Static SNAT bi-directional, an implied DNAT rule will be derived from your SNAT one (szone [any],sip [any] - dzone [same],dip [snated ip]).&lt;BR /&gt;You can see it with # show running nat-policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In you case, I think something is wrong with routing (maybe a wrong mask), your source IP from DMZ zone seems to be routed back in trust zone...&lt;BR /&gt;furthermore, don't forget to keep your pre-NAT IP address in your security policy to allow the traffic..&lt;/P&gt;&lt;P&gt;Hope this will help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;-Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Jan 2013 16:14:37 GMT</pubDate>
    <dc:creator>nbilly</dc:creator>
    <dc:date>2013-01-09T16:14:37Z</dc:date>
    <item>
      <title>Zone Assignment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-assignment/m-p/46192#M33945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In PanOS, how are the zones established for inbound rules?&amp;nbsp; I have a bi-directional NAT created for a device located in a DMZ.&amp;nbsp; I also have a security policy allowing traffic to the NAT address from the untrusted zone (Internet).&amp;nbsp; When traffic comes in, it is marked as source zone =&amp;gt; untrusted, destination zone =&amp;gt; trusted and denied because there is no policy for untrusted to trusted.&amp;nbsp; Shouldn't the destination zone be my DMZ?&amp;nbsp; See attached file for the log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 14:59:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-assignment/m-p/46192#M33945</guid>
      <dc:creator>jpvh1234</dc:creator>
      <dc:date>2013-01-09T14:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Assignment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-assignment/m-p/46193#M33946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jeff,&lt;/P&gt;&lt;P&gt;For NAT rules, zone matching is based on ingress interface and egress interface after PBF policy or route table lookup.&lt;BR /&gt;Zone matching for Security rules is a post nat process; so a second lookup will occur after applying destination NAT rule (if there was a Nat policy match).&lt;BR /&gt;on the other side, for ip matching, in security policy, you always have to keep pre-NAT IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using Static SNAT bi-directional, an implied DNAT rule will be derived from your SNAT one (szone [any],sip [any] - dzone [same],dip [snated ip]).&lt;BR /&gt;You can see it with # show running nat-policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In you case, I think something is wrong with routing (maybe a wrong mask), your source IP from DMZ zone seems to be routed back in trust zone...&lt;BR /&gt;furthermore, don't forget to keep your pre-NAT IP address in your security policy to allow the traffic..&lt;/P&gt;&lt;P&gt;Hope this will help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;-Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 16:14:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-assignment/m-p/46193#M33946</guid>
      <dc:creator>nbilly</dc:creator>
      <dc:date>2013-01-09T16:14:37Z</dc:date>
    </item>
  </channel>
</rss>

