<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT question when migrating config. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question-when-migrating-config/m-p/73405#M41424</link>
    <description>&lt;P&gt;Servers accesible from internet should be in DMZ. They should have only necessary services/applications open towards LAN. So if a server is breached, attacker still has no access into LAN and other networks (or very limited).&lt;/P&gt;
&lt;P&gt;In what cases would you need direct access from internet to LAN?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Feb 2016 08:05:45 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2016-02-24T08:05:45Z</dc:date>
    <item>
      <title>NAT question when migrating config.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question-when-migrating-config/m-p/73401#M41421</link>
      <description>&lt;P&gt;Converting config from Nortel Connectivty switch to PA200.&lt;/P&gt;
&lt;P&gt;3 interfaces&lt;/P&gt;
&lt;P&gt;untrust - public ip - 202.3.41.0/28&lt;/P&gt;
&lt;P&gt;trust:private ip - 10.10.10.0/24.&lt;/P&gt;
&lt;P&gt;dmz-203.4.42.96/28&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is one to one mapping of few untrust ip to trust ips( to access trust ips from outside) and also few one to one mapping from dmz to trust.&lt;/P&gt;
&lt;P&gt;When translating this to PA200.&lt;/P&gt;
&lt;P&gt;I can do untrust to trust fine adding nat and security rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when doing dmz to trust not sure about security polices and nat rules.&lt;/P&gt;
&lt;P&gt;Will it be untrust to dmz(eg-203.4.42.99) -destination address translation ,translated address 10.10.10.100 in nat rule and untrust to trust(203.4.42.99) in security rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 05:34:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-question-when-migrating-config/m-p/73401#M41421</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2016-02-24T05:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question when migrating config.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question-when-migrating-config/m-p/73403#M41422</link>
      <description>&lt;P&gt;I think it will be like that yes. But it's a bit weird concept i haven't seen yet. Are there also some servers with public address in DMZ? Or are there only NAT-ed servers? If it's only NAT-ed servers in DMZ than you can easily skip configuring DMZ on seperate interface and just configure that segment on untrust interface.&lt;/P&gt;
&lt;P&gt;Nothing to do with your original question: but&amp;nbsp;NAT into LAN is a very poor design regarding security. So if you have a chance try to redisgn the network.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 07:15:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-question-when-migrating-config/m-p/73403#M41422</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-02-24T07:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question when migrating config.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question-when-migrating-config/m-p/73404#M41423</link>
      <description>&lt;P&gt;thanks for the info. But if you dont NAT in LAN how do u access LAN from untrust if u need to. Do u move them to dmz and just&lt;/P&gt;
&lt;P&gt;have untrust to dmz access?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 07:42:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-question-when-migrating-config/m-p/73404#M41423</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2016-02-24T07:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question when migrating config.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-question-when-migrating-config/m-p/73405#M41424</link>
      <description>&lt;P&gt;Servers accesible from internet should be in DMZ. They should have only necessary services/applications open towards LAN. So if a server is breached, attacker still has no access into LAN and other networks (or very limited).&lt;/P&gt;
&lt;P&gt;In what cases would you need direct access from internet to LAN?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 08:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-question-when-migrating-config/m-p/73405#M41424</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-02-24T08:05:45Z</dc:date>
    </item>
  </channel>
</rss>

