<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route outgoing gmail application received on specific internal interface out different Public IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/route-outgoing-gmail-application-received-on-specific-internal/m-p/49965#M36767</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use PBF using a Dynamic Address Object.&lt;/P&gt;&lt;P&gt;Check &lt;A href="https://support.google.com/a/answer/60764" title="https://support.google.com/a/answer/60764"&gt;Google IP address ranges&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can then set up a cron task to push Google IP addresses to the Dynamic Address object.&lt;/P&gt;&lt;P&gt;Refer to &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6672"&gt;How to Add an IP Address to a Dynamic Address Group using API&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could alternatively leverage information to create an EBL from radb.net and shadowserver.org as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;mivaldi$ ping www.google.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;PING www.google.com (&lt;STRONG&gt;74.125.239.49&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; 56 data bytes&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;64 bytes from 74.125.239.49: icmp_seq=0 ttl=54 time=2.506 ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;^C&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;--- www.google.com ping statistics ---&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;1 packets transmitted, 1 packets received, 0.0% packet loss&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;round-trip min/avg/max/stddev = 2.506/2.506/2.506/0.000 ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;mivaldi$ whois -h asn.shadowserver.org "origin &lt;STRONG&gt;74.125.239.49&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;15169&lt;/STRONG&gt; | 74.125.239.0/24 | GOOGLE | US | google.com | Google Inc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;mivaldi$ whois -h whois.radb.net -- '-i origin &lt;STRONG&gt;AS15169&lt;/STRONG&gt;' | grep ^route&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 66.249.64.0/20&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 66.249.80.0/20&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 194.110.194.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 74.125.57.240/29&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 193.142.125.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 193.186.4.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 193.200.222.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 216.239.44.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 216.239.45.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;All known google AS15169 IP's&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Jul 2014 21:28:16 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2014-07-18T21:28:16Z</dc:date>
    <item>
      <title>Route outgoing gmail application received on specific internal interface out different Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-outgoing-gmail-application-received-on-specific-internal/m-p/49964#M36766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to figure out the best and easiest way to route all gmail application (gmail-base and gmail-enterprise primarily) that enters on an internal port from one network and send it out using a separate pubic IP we have. Currently all internet based outbound traffic goes out a using a single IP and we are having an issue with that IP getting MX blacklisted by Barracuda. I am suspecting that this internal network port is where the "promotional material" is being sent out and since we have several networks all using the same public IP for outbound general internet, they are all affected by this. So I have the gmail web IP blocks identified that I would like to use either NAT and/or PBF to take all traffic received on that internal network interface and send it out using a separate public IP we have so when they abuse the limits that Barracuda sets for identifying spam sources, it only affects their internal network. Since the gmail application can't be used in a PBF, I'm struggling to find another way other than sending all their outbound internet traffic out a separate IP which would require more setup. Unfortunately, they are in the same Zone as all our internal networks connected to the PA also. Is there anything I can do easily or will I have to look at separating out the Zones also?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jul 2014 21:01:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-outgoing-gmail-application-received-on-specific-internal/m-p/49964#M36766</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-07-17T21:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: Route outgoing gmail application received on specific internal interface out different Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-outgoing-gmail-application-received-on-specific-internal/m-p/49965#M36767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use PBF using a Dynamic Address Object.&lt;/P&gt;&lt;P&gt;Check &lt;A href="https://support.google.com/a/answer/60764" title="https://support.google.com/a/answer/60764"&gt;Google IP address ranges&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can then set up a cron task to push Google IP addresses to the Dynamic Address object.&lt;/P&gt;&lt;P&gt;Refer to &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6672"&gt;How to Add an IP Address to a Dynamic Address Group using API&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could alternatively leverage information to create an EBL from radb.net and shadowserver.org as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;mivaldi$ ping www.google.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;PING www.google.com (&lt;STRONG&gt;74.125.239.49&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; 56 data bytes&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;64 bytes from 74.125.239.49: icmp_seq=0 ttl=54 time=2.506 ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;^C&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;--- www.google.com ping statistics ---&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;1 packets transmitted, 1 packets received, 0.0% packet loss&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;round-trip min/avg/max/stddev = 2.506/2.506/2.506/0.000 ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;mivaldi$ whois -h asn.shadowserver.org "origin &lt;STRONG&gt;74.125.239.49&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;15169&lt;/STRONG&gt; | 74.125.239.0/24 | GOOGLE | US | google.com | Google Inc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;mivaldi$ whois -h whois.radb.net -- '-i origin &lt;STRONG&gt;AS15169&lt;/STRONG&gt;' | grep ^route&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 66.249.64.0/20&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 66.249.80.0/20&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 194.110.194.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 74.125.57.240/29&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 193.142.125.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 193.186.4.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 193.200.222.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 216.239.44.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;route:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 216.239.45.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;All known google AS15169 IP's&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2014 21:28:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-outgoing-gmail-application-received-on-specific-internal/m-p/49965#M36767</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2014-07-18T21:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Route outgoing gmail application received on specific internal interface out different Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-outgoing-gmail-application-received-on-specific-internal/m-p/49966#M36768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks that is good knowledge to have, but my bigger issue is trying to send just traffic received on an internal port ethernet1/105 and NAT it out a separate public IP in our block. I want to leave the other Internal networks connected to different physical ports to continue to use the primary outbound internet NAT rule for all traffic. We're getting the primary public IP which is what all outbound internet connections use blacklisted and I suspect it is the hosts I have on this internal interface ethernet1/105 that is causing it.&amp;nbsp; Does that make sense? I already have the gmail ranges identified statically assigned to an address group, but will look at doing it dynamically too. Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2014 21:44:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-outgoing-gmail-application-received-on-specific-internal/m-p/49966#M36768</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-07-18T21:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Route outgoing gmail application received on specific internal interface out different Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-outgoing-gmail-application-received-on-specific-internal/m-p/49967#M36769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about a PBF like this (Interfaces and Next Hop will be different for you).&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14570" alt="Screen Shot 2014-07-18 at 2.56.14 PM.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14570_Screen Shot 2014-07-18 at 2.56.14 PM.png" style="height: 224px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14571" alt="Screen Shot 2014-07-18 at 2.56.20 PM.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14571_Screen Shot 2014-07-18 at 2.56.20 PM.png" style="height: 352px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14573" alt="Screen Shot 2014-07-18 at 2.57.54 PM.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14573_Screen Shot 2014-07-18 at 2.57.54 PM.png" style="height: 351px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14574" alt="Screen Shot 2014-07-18 at 2.58.18 PM.png" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/14574_Screen Shot 2014-07-18 at 2.58.18 PM.png" style="height: 477px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following the sequence of events, NAT is evaluated (before PBF, to determine Destination Zone for Security Policies), then PBF is implemented, then NAT is implemented.&lt;/P&gt;&lt;P&gt;Therefore next step is to do NAT based on the Destination Address object for GMail:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14637" alt="Screen Shot 2014-07-22 at 11.12.43 AM.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14637_Screen Shot 2014-07-22 at 11.12.43 AM.png" style="height: 251px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14638" alt="Screen Shot 2014-07-22 at 11.13.27 AM.png" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/14638_Screen Shot 2014-07-22 at 11.13.27 AM.png" style="height: 327px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14639" alt="Screen Shot 2014-07-22 at 11.14.10 AM.png" class="jive-image image-3" src="https://live.paloaltonetworks.com/legacyfs/online/14639_Screen Shot 2014-07-22 at 11.14.10 AM.png" style="height: 247px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2014 21:59:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-outgoing-gmail-application-received-on-specific-internal/m-p/49967#M36769</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2014-07-18T21:59:10Z</dc:date>
    </item>
  </channel>
</rss>

