<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect - External IP as source in VPN tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-ip-as-source-in-vpn-tunnel/m-p/50200#M36969</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...The remote client should be NAT'ed to one of the IPs in the VPN's ip pool if the traffic is going thru the VPN tunnel.&amp;nbsp; The VPN tunnel should be on a different zone than the public external zone.&amp;nbsp; Please take a look at the traffic log and check the src zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you still need help, please open a case with Support.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Jun 2012 19:34:30 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2012-06-06T19:34:30Z</dc:date>
    <item>
      <title>Global Protect - External IP as source in VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-ip-as-source-in-vpn-tunnel/m-p/50199#M36968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello PAN.&lt;/P&gt;&lt;P&gt;Trying to figure out why my connection on the VPN client was behaving a bit sporadic I noticed that *some* of the traffic send to the firewall from my GPA was using source IP = my client public IP, rather than my client private IP.&lt;/P&gt;&lt;P&gt;So. Some traffic is send with source IP = public IP, some traffic is being send with source IP = vpn IP.&lt;/P&gt;&lt;P&gt;VPN client i is tunnel mode, where only traffic to internal systems are being send to the firewall.&lt;/P&gt;&lt;P&gt;How can we make sure that tunnel traffic is only using source IP = vpn IP (so that it doesn't get dropped on the firewall) ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jørgen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 05:48:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-ip-as-source-in-vpn-tunnel/m-p/50199#M36968</guid>
      <dc:creator>sitecore</dc:creator>
      <dc:date>2012-06-06T05:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - External IP as source in VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-ip-as-source-in-vpn-tunnel/m-p/50200#M36969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...The remote client should be NAT'ed to one of the IPs in the VPN's ip pool if the traffic is going thru the VPN tunnel.&amp;nbsp; The VPN tunnel should be on a different zone than the public external zone.&amp;nbsp; Please take a look at the traffic log and check the src zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you still need help, please open a case with Support.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 19:34:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-ip-as-source-in-vpn-tunnel/m-p/50200#M36969</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-06-06T19:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - External IP as source in VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-ip-as-source-in-vpn-tunnel/m-p/50201#M36970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes - it *should* NAT with the VPN IP. But if I log dropped traffic on the firewall I see:&lt;/P&gt;&lt;P&gt;Inbound interface = VPN Tunnel interface&lt;/P&gt;&lt;P&gt;Source zone = our VPN zone&lt;/P&gt;&lt;P&gt;Source IP = my public IP&lt;/P&gt;&lt;P&gt;Destination zone = our internal zone (any of them &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; )&lt;/P&gt;&lt;P&gt;Destination IP = internal IP&lt;/P&gt;&lt;P&gt;So it is certainly not NAT'ing *all* the traffic. It's a bit of both - which of course cannot be good for performence.&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;Jørgen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 19:49:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-ip-as-source-in-vpn-tunnel/m-p/50201#M36970</guid>
      <dc:creator>sitecore</dc:creator>
      <dc:date>2012-06-06T19:49:25Z</dc:date>
    </item>
  </channel>
</rss>

