<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect with NATet interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46900#M34462</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is working as expected.&amp;nbsp; If you are NATing 443 from the outside to an inside server you loose access to the management page.&amp;nbsp; You can set up a loopback and NAT another port to 443 on the loopback with an management profile that allows HTTPS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Feb 2014 19:53:05 GMT</pubDate>
    <dc:creator>JimS2</dc:creator>
    <dc:date>2014-02-07T19:53:05Z</dc:date>
    <item>
      <title>GlobalProtect with NATet interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46898#M34460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a PA200, and is using eth1 for outside (internet) and eth2 for inside. I'm NATing from eth2 to eth1, as normal.&lt;/P&gt;&lt;P&gt;Now i want to have the management https address on the eth1 for several reasons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At home its just for testing, but at my office i have PA200 between subnets that is duplicate, and not nessesary to route to.&lt;/P&gt;&lt;P&gt;When i use a management profile with access to ping and https on eth1, it wont't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect the NAT rule has something to do with it. Cause when i set it up in my lab with no NAT, it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any tips for me please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Feb 2014 19:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46898#M34460</guid>
      <dc:creator>tormodhope</dc:creator>
      <dc:date>2014-02-05T19:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with NATet interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46899#M34461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got it working with a DNAT against the outside ip address. But is this needed?&lt;/P&gt;&lt;P&gt;Is there another way doing it? The IP is public and facing internet, i though a management profile would open anyway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Feb 2014 19:56:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46899#M34461</guid>
      <dc:creator>tormodhope</dc:creator>
      <dc:date>2014-02-05T19:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with NATet interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46900#M34462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is working as expected.&amp;nbsp; If you are NATing 443 from the outside to an inside server you loose access to the management page.&amp;nbsp; You can set up a loopback and NAT another port to 443 on the loopback with an management profile that allows HTTPS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2014 19:53:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46900#M34462</guid>
      <dc:creator>JimS2</dc:creator>
      <dc:date>2014-02-07T19:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with NATet interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46901#M34463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/26213"&gt;tormodhope&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May be you are experiencing the land attack. When we access the external interface from outside the source will be external host public IP and destination will be your external interface IP. When the return traffic is sent out ( server to client s2c ) it exchanges the source and destination and gets stuck seeing the source and destination the same considers a land attack and drops.&lt;/P&gt;&lt;P&gt;If you do&lt;/P&gt;&lt;P&gt;"show counter global filter delta yes | match land"&lt;/P&gt;&lt;P&gt;If the counters are seen then that would prove it. We will have to change the nat slightly and it should start to work.&lt;/P&gt;&lt;P&gt;Details are mentioned in the below doc:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3367"&gt;Unable to Connect to or Ping a Firewall Interface&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2014 20:25:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46901#M34463</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2014-02-07T20:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with NATet interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46902#M34464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2890"&gt;How to Access the WebUI when GlobalProtect Is Enabled&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Your subject is about GP so just to remind you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2014 22:43:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46902#M34464</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-02-07T22:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with NATet interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46903#M34465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont NAT anything from untrust to trust, i only have a overload nat from trust to untrust.&lt;/P&gt;&lt;P&gt;But it seams that it blocks everything, including ping, and https (thats why the GP wont connect).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 08:33:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46903#M34465</guid>
      <dc:creator>tormodhope</dc:creator>
      <dc:date>2014-02-10T08:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with NATet interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46904#M34466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks! I'll try that later today.&lt;/P&gt;&lt;P&gt;I got ping working if i add a roule thats like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 02-10-14 at 09.40 AM.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11500_Screen Shot 02-10-14 at 09.40 AM.PNG.png" style="width: 620px; height: 44px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0.0.0.0/0 is just there to mas my origin public ip. The other rule is gone, as this is a test box at work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 08:43:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46904#M34466</guid>
      <dc:creator>tormodhope</dc:creator>
      <dc:date>2014-02-10T08:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with NATet interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46905#M34467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This rule is not a need but your other NAT rules are important.you have any other NAT rule with source zone any ?&lt;/P&gt;&lt;P&gt;or just 1 NAT rule from trust to untrust ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 09:08:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46905#M34467</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-02-10T09:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with NATet interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46906#M34468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since im not home now, i cant confirm, but yes, i might have to rule setup with source any, and not pined down to my trust zones.&lt;/P&gt;&lt;P&gt;This is bad practice, i know. But is that the problem? I'll doublecheck when i get home.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rule might be like this one, with source any.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 02-10-14 at 10.12 AM.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11504_Screen Shot 02-10-14 at 10.12 AM.PNG.png" style="width: 620px; height: 47px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 09:16:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46906#M34468</guid>
      <dc:creator>tormodhope</dc:creator>
      <dc:date>2014-02-10T09:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with NATet interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46907#M34469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it will be a problem as &lt;SPAN class="j-post-author"&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1818" data-externalid="" data-presence="null" data-userid="8931" data-username="Phoenix" href="https://live.paloaltonetworks.com/people/Phoenix"&gt;Phoenix&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt; said.&lt;/P&gt;&lt;P&gt;Try to change it with Trust and then test again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 09:19:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-natet-interface/m-p/46907#M34469</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-02-10T09:19:34Z</dc:date>
    </item>
  </channel>
</rss>

