<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: configuration of the NAT rules to DMZ zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67203#M39458</link>
    <description>&lt;P&gt;Thank you very moch&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;. It work fine now after this modification &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for all helps&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Oct 2015 12:52:30 GMT</pubDate>
    <dc:creator>RCHAIBI</dc:creator>
    <dc:date>2015-10-23T12:52:30Z</dc:date>
    <item>
      <title>configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/66931#M39377</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our office we have two servers in a DMZ zone (10.10.10.3 and 10.10.10.4). In the PA-500 I created a DMZ zone that's related to a vlan in the switch . This switch i related to the serves&amp;nbsp;&lt;SPAN&gt;(10.10.10.3 and 10.10.10.4).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The servers are in DMZ zone so I configure the NAT rules with static NAT and I open the necessary ports. But without any results. I think that I shoudn't configure a destinaion NAT in this cas becous the servers ar in DMZ zone and ot in a LAN zone.&lt;/P&gt;
&lt;P&gt;You wil find in the attchment the screenshot about the existing configuration of PAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will be appreciated for all helps !&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/804i77E8EA95571A43B6/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="NAT-cisco.JPG" title="NAT-cisco.JPG" /&gt;&lt;/P&gt;
&lt;P&gt;Thank you very much &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 21:22:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/66931#M39377</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-10-20T21:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/66936#M39378</link>
      <description>&lt;P&gt;Move first rule to bottom.&lt;/P&gt;
&lt;P&gt;Are other rules bi-directional?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 21:57:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/66936#M39378</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-20T21:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/66937#M39379</link>
      <description>&lt;P&gt;Also try to get one rule working first.&lt;/P&gt;
&lt;P&gt;You try to map multiple ports to single port (all wan side ports are 25 but internal ones are diferent).&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 22:01:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/66937#M39379</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-20T22:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/66941#M39382</link>
      <description>&lt;P&gt;Without more of the rulesset, I would assume you probably need a U-Turn rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Understanding-PAN-OS-NAT/ta-p/60965" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Understanding-PAN-OS-NAT/ta-p/60965&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will allow the traffic to get to the proper server. It's a NAT and a Security Policy combo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 22:57:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/66941#M39382</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-10-20T22:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/66980#M39392</link>
      <description>&lt;P&gt;You cannot map the same ip/port (25) to three different internal ip/port combinations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Static NAT is &amp;nbsp;a one-to-one bidirectional NAT so there can only be one external ip/port to one internal ip/port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the situation here, are you looking for inbound NAT rules to expose multiple DMZ servers for SMTP?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 10:32:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/66980#M39392</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-10-21T10:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67078#M39416</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm sorry i do a mistake when i wrote the table of the NAT rules. You will find in the attachement the right screen shot . The static NAT that i used is a bidirectional NAT. I add also a security rules to access to the email server (10.10.10.2) . The problem that i can send an email but i can't receive any email. I think that i do a mistake in the security rules. Could you please help me to determinate the mistake in my configuration.&lt;/P&gt;
&lt;P&gt;Thank you very much for all helps&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/884i25D0539606EB4E1E/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="NAT-rules.PNG" title="NAT-rules.PNG" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/883i7BF8523A76C7B798/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="security-rules.PNG" title="security-rules.PNG" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2015 11:34:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67078#M39416</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-10-22T11:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67079#M39417</link>
      <description>&lt;P&gt;Your WAN to DMZ security policy should read:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;srcZN:&lt;STRONG&gt;WAN&lt;/STRONG&gt; srcADR:&lt;STRONG&gt;any&lt;/STRONG&gt; dstZN:&lt;STRONG&gt;DMZ&lt;/STRONG&gt; dstADR:&lt;STRONG&gt;193.200.1.25&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for a security policy the IP addressing are preNAT, zones are postNAT&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2015 11:48:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67079#M39417</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-10-22T11:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67203#M39458</link>
      <description>&lt;P&gt;Thank you very moch&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;. It work fine now after this modification &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for all helps&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 12:52:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67203#M39458</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-10-23T12:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67204#M39459</link>
      <description>&lt;P&gt;I found a problem with the 443 port . I add a NAT rule like shooing in the screen shoot to the 443 port and i add a security rules from outside to dmz ( with public ip address and the port443)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But without any result this port still always closed&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for all helps&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 12:55:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67204#M39459</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-10-23T12:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67205#M39460</link>
      <description>&lt;P&gt;the NAT for port 25 is going to 10.10.10.2 while 443 is going to 10.10.10.3, did you make sure port 443 is accessible on that server and the nat/security rules are identical except for the ports and the server ip?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 13:17:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67205#M39460</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-10-23T13:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67206#M39461</link>
      <description>&lt;P&gt;The port 443 is open in the server 10.10.10.3 and i do the same security rules but always thsi port is used by the&amp;nbsp;PAN , should i change the default management port of the PAN like presented in this article&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Change-the-Default-Management-Port/ta-p/62333" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Change-the-Default-Management-Port/ta-p/62333&lt;/A&gt; ??&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 13:33:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67206#M39461</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-10-23T13:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67209#M39464</link>
      <description>&lt;P&gt;Yes ,the port &amp;nbsp;443 is open in the server 10.10.10.3 and I do the same configuration that i did it to open the 25 port in the server 10.10.10.2. when i activate the https on the outside port . This port is change to open but to the interface of the configuration of the PAN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should i change the default ports used by the PAN like show this article ??&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Change-the-Default-Management-Port/ta-p/62333" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Change-the-Default-Management-Port/ta-p/62333&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 13:43:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67209#M39464</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-10-23T13:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67210#M39465</link>
      <description>&lt;P&gt;if you have a management profile configured on the interface with ssl enabled, you would be redirected to the GUI, but if there's no management profile or ssl has not been enabled you don't need to implement that article.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you seeing anything in the logs?&lt;/P&gt;
&lt;P&gt;you should be able to figure out what is going on by trying this cli command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show session all filter destination 193.200.1.25 destination-port 443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and then get the full view for the session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show session id &amp;lt;id&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this will show you if NAT is being applied properly and which security/nat rules you are hitting:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Session              23

        c2s flow:
                source:      10.10.10.15 [trust]
                dst:         198.51.100.2
                proto:       17
                sport:       35040           dport:      22
                state:       ACTIVE          type:       FLOW
                src user:    unknown
                dst user:    unknown


        s2c flow:
                source:      198.51.100.2[untrust]
                &lt;STRONG&gt;dst:         198.51.100.22&lt;/STRONG&gt;
                proto:       17
                sport:       22            dport:      35040
                state:       ACTIVE          type:       FLOW
                src user:    unknown
                dst user:    unknown

       start time                           : Tue Oct 20 13:49:57 2015
        timeout                              : 3600 sec
        time to live                         : 3592 sec 
        total byte count(c2s)                : 13026788
        total byte count(s2c)                : 12878618
        layer7 packet count(c2s)             : 84918
        layer7 packet count(s2c)             : 84943
        vsys                                 : vsys1
        application                          : ssh  
        &lt;STRONG&gt;rule                                 : securityrule_1&lt;/STRONG&gt;
        session to be logged at end          : True
        session in session ager              : True
        session updated by HA peer           : False
        address/port translation             : source
        &lt;STRONG&gt;nat-rule                             : nat_rule&lt;/STRONG&gt;(vsys1)
        layer7 processing                    : enabled
        URL filtering enabled                : True
        URL category                         : any
        session via syn-cookies              : False
        session terminated on host           : False
        session traverses tunnel             : False
        captive portal session               : False
        ingress interface                    : ethernet1/2
        egress interface                     : ethernet1/1
        session QoS rule                     : N/A (class 4)
        end-reason                           : unknown
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 13:57:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67210#M39465</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-10-23T13:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: configuration of the NAT rules to DMZ zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67213#M39467</link>
      <description>&lt;P&gt;It's OK&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;, it's a problem with the access list thank you very much &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 14:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-the-nat-rules-to-dmz-zone/m-p/67213#M39467</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-10-23T14:48:32Z</dc:date>
    </item>
  </channel>
</rss>

