<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT rule being applied wrong in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-being-applied-wrong/m-p/65350#M39029</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a static NAT from this ip &lt;SPAN&gt;192.168.200.8&lt;/SPAN&gt; (zone DMZ) &amp;nbsp;to 195.57. (zone VPN). But we&amp;nbsp;realised that the NAT rule which is matching is wrong.&lt;/P&gt;&lt;P&gt;Its matching the NAT rule (ftp.arag.es) but this rule has a filter by "Destination zone" Externa. And the real traffic is VPN&amp;lt;-&amp;gt;DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why PA is applying this rule if not being include the destiantion zone in the filter???&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
    <pubDate>Fri, 02 Oct 2015 09:12:18 GMT</pubDate>
    <dc:creator>SOC_CSG</dc:creator>
    <dc:date>2015-10-02T09:12:18Z</dc:date>
    <item>
      <title>NAT rule being applied wrong</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-being-applied-wrong/m-p/65350#M39029</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a static NAT from this ip &lt;SPAN&gt;192.168.200.8&lt;/SPAN&gt; (zone DMZ) &amp;nbsp;to 195.57. (zone VPN). But we&amp;nbsp;realised that the NAT rule which is matching is wrong.&lt;/P&gt;&lt;P&gt;Its matching the NAT rule (ftp.arag.es) but this rule has a filter by "Destination zone" Externa. And the real traffic is VPN&amp;lt;-&amp;gt;DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why PA is applying this rule if not being include the destiantion zone in the filter???&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 09:12:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-being-applied-wrong/m-p/65350#M39029</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-10-02T09:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule being applied wrong</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-being-applied-wrong/m-p/65356#M39034</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm guessing you need a U-Turn NAT rule so the VPN clients can communicate properly to the external FTP site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Understanding-PAN-OS-NAT/ta-p/60965" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Understanding-PAN-OS-NAT/ta-p/60965&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a good article and covers all the NAT types.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 14:13:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-being-applied-wrong/m-p/65356#M39034</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-10-01T14:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule being applied wrong</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-being-applied-wrong/m-p/65374#M39046</link>
      <description>&lt;P&gt;when you create a bidirectional policy, a return policy is created in the background. You can see it just using the CLI&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show running nat-policy&lt;/P&gt;&lt;P&gt;The return policy changes the&amp;nbsp;destination zone to any and put it as source. so In your case the return policy is going to be&lt;/P&gt;&lt;P&gt;From zone: any&lt;/P&gt;&lt;P&gt;To zone: DMZ&lt;/P&gt;&lt;P&gt;To: 192.57.58.218&lt;/P&gt;&lt;P&gt;Translate to: 192.168.200.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gerardo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 19:30:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-being-applied-wrong/m-p/65374#M39046</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2015-10-01T19:30:19Z</dc:date>
    </item>
  </channel>
</rss>

