<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I publish a Server via a public IP from the same Subnet of the WAN Interface? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51730#M38056</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I'm new to PAN Firewalls and currently I am trying to publish a customer's SBS Server via a PAN200. The Firewall has the public IP 218.1.1.218(of course i posted a fake one &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;) and the server shall be accessible via 218.1.1.220. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I've configured Accessrules allowing traffic from WAN to LAN + SBS internal IP&lt;/P&gt;&lt;P&gt;-&amp;nbsp; Static unidirectional NAT for LAN -&amp;gt; WAN source sbs internal to 218.1.1.220&lt;/P&gt;&lt;P&gt;- Destination NAT for WAN -&amp;gt; WAN destination 218.1.1.220 to SBS internal IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried to reach the server and I can't find anything recorder in traffic monitoring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope someone has a idea to solve this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Aug 2013 09:34:44 GMT</pubDate>
    <dc:creator>vertical</dc:creator>
    <dc:date>2013-08-06T09:34:44Z</dc:date>
    <item>
      <title>How can I publish a Server via a public IP from the same Subnet of the WAN Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51730#M38056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I'm new to PAN Firewalls and currently I am trying to publish a customer's SBS Server via a PAN200. The Firewall has the public IP 218.1.1.218(of course i posted a fake one &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;) and the server shall be accessible via 218.1.1.220. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I've configured Accessrules allowing traffic from WAN to LAN + SBS internal IP&lt;/P&gt;&lt;P&gt;-&amp;nbsp; Static unidirectional NAT for LAN -&amp;gt; WAN source sbs internal to 218.1.1.220&lt;/P&gt;&lt;P&gt;- Destination NAT for WAN -&amp;gt; WAN destination 218.1.1.220 to SBS internal IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried to reach the server and I can't find anything recorder in traffic monitoring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope someone has a idea to solve this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 09:34:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51730#M38056</guid>
      <dc:creator>vertical</dc:creator>
      <dc:date>2013-08-06T09:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can I publish a Server via a public IP from the same Subnet of the WAN Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51731#M38057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Try to telnet from outside to that 220 ip for the related port and see from monitor if it shows the logs and NAT works or not&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 09:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51731#M38057</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-06T09:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: How can I publish a Server via a public IP from the same Subnet of the WAN Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51732#M38058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;doesn't get logged either &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 09:47:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51732#M38058</guid>
      <dc:creator>vertical</dc:creator>
      <dc:date>2013-08-06T09:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: How can I publish a Server via a public IP from the same Subnet of the WAN Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51733#M38059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you type your security rule and Nat rule for that traffic with details&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 09:51:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51733#M38059</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-06T09:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: How can I publish a Server via a public IP from the same Subnet of the WAN Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51734#M38060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you filtering the the traffic logs with destination set to the external IP address ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 10:01:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51734#M38060</guid>
      <dc:creator>harshanatarajan</dc:creator>
      <dc:date>2013-08-06T10:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: How can I publish a Server via a public IP from the same Subnet of the WAN Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51735#M38061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;security rule:&lt;/P&gt;&lt;P&gt;source zone: WAN any any any&lt;/P&gt;&lt;P&gt;dest zone: LAN SBS_internal&lt;/P&gt;&lt;P&gt;application and service: any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT:&lt;/P&gt;&lt;P&gt;rule 1:&lt;/P&gt;&lt;P&gt;src zone: LAN src address SBS_internal&lt;/P&gt;&lt;P&gt;dst zone: WAN&lt;/P&gt;&lt;P&gt;static nat: 218.1.1.220&lt;/P&gt;&lt;P&gt;bi directional: no&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rule 2:&lt;/P&gt;&lt;P&gt;src zone: WAN&lt;/P&gt;&lt;P&gt;dst zone: WAN dst address 218.1.1.220&lt;/P&gt;&lt;P&gt;Dest NAT: SBS_internal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all rules are on top, so nat+pat doesn't hit traffic from the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pinged 8.8.8.8 from the server and it was sucessfully nat'ed to the expected public IP and replies came back in. however inbound connections are not logged for this public ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yep also filtered the logs for the specific ip or WAN as dst zone, but even without filters i didn't see the traffic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 10:11:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51735#M38061</guid>
      <dc:creator>vertical</dc:creator>
      <dc:date>2013-08-06T10:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: How can I publish a Server via a public IP from the same Subnet of the WAN Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51736#M38062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;change SBS_internal to public ip address on security rule&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 10:16:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51736#M38062</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-06T10:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: How can I publish a Server via a public IP from the same Subnet of the WAN Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51737#M38063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you specified the external ip address in the security rule ? If not can you specify the pre NAT address in the destination address field. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 10:16:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51737#M38063</guid>
      <dc:creator>harshanatarajan</dc:creator>
      <dc:date>2013-08-06T10:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: How can I publish a Server via a public IP from the same Subnet of the WAN Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51738#M38064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks guys, that was indeed the problem &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for those wondering why the traffic was dropped but not logged: you need to define a rule that matches a drop, the default deny rule does not log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 10:34:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-publish-a-server-via-a-public-ip-from-the-same-subnet/m-p/51738#M38064</guid>
      <dc:creator>vertical</dc:creator>
      <dc:date>2013-08-06T10:34:38Z</dc:date>
    </item>
  </channel>
</rss>

