<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT over IPSEC VPN without an IP on the Tunnel interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn-without-an-ip-on-the-tunnel-interface/m-p/73744#M41516</link>
    <description>&lt;P&gt;What kind of NAT are you trying to do?&lt;/P&gt;
&lt;P&gt;It is possible to do dynamic-ip-and-port source NAT for sure, I haven't triend other scenarios.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Feb 2016 06:36:15 GMT</pubDate>
    <dc:creator>mvidic</dc:creator>
    <dc:date>2016-02-29T06:36:15Z</dc:date>
    <item>
      <title>NAT over IPSEC VPN without an IP on the Tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn-without-an-ip-on-the-tunnel-interface/m-p/73724#M41515</link>
      <description>&lt;P&gt;Does anyone know if it is possible to NAT over an IPSEC VPN without assigning&amp;nbsp;an IP address on the tunnel interface itself?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried but it doesn't&amp;nbsp;seem possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Duane&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2016 01:18:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn-without-an-ip-on-the-tunnel-interface/m-p/73724#M41515</guid>
      <dc:creator>Hensley</dc:creator>
      <dc:date>2016-02-28T01:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAT over IPSEC VPN without an IP on the Tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn-without-an-ip-on-the-tunnel-interface/m-p/73744#M41516</link>
      <description>&lt;P&gt;What kind of NAT are you trying to do?&lt;/P&gt;
&lt;P&gt;It is possible to do dynamic-ip-and-port source NAT for sure, I haven't triend other scenarios.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Feb 2016 06:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn-without-an-ip-on-the-tunnel-interface/m-p/73744#M41516</guid>
      <dc:creator>mvidic</dc:creator>
      <dc:date>2016-02-29T06:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAT over IPSEC VPN without an IP on the Tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn-without-an-ip-on-the-tunnel-interface/m-p/73750#M41519</link>
      <description>&lt;P&gt;Hi Duane&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can try adding a loopback interface in the same zone as the vpn interface, then create a nat rule using dynamic ip+port and nat sourced from the loopback&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2816i03D42EA1863AC413/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2016-02-29_08-13-10.png" title="2016-02-29_08-13-10.png" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2817iFB34FD8C43043C5D/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2016-02-29_08-14-57.png" title="2016-02-29_08-14-57.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;depending on your remote peer you may need to account for this by using proxy-IDs&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2818i7E53BC006189CD15/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2016-02-29_08-17-12.png" title="2016-02-29_08-17-12.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;</description>
      <pubDate>Mon, 29 Feb 2016 07:17:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn-without-an-ip-on-the-tunnel-interface/m-p/73750#M41519</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-02-29T07:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAT over IPSEC VPN without an IP on the Tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn-without-an-ip-on-the-tunnel-interface/m-p/74285#M41651</link>
      <description>&lt;P&gt;If you want to &amp;nbsp;configure a NAT rule you should be having an ip address on the interface either statically or assisgned via DHCP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Else that will &amp;nbsp;be a Not nat rule for the traffic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you trying to &amp;nbsp;use tunnel interface in NAT rule &amp;nbsp;?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 16:41:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-over-ipsec-vpn-without-an-ip-on-the-tunnel-interface/m-p/74285#M41651</guid>
      <dc:creator>tsrivastav</dc:creator>
      <dc:date>2016-03-07T16:41:26Z</dc:date>
    </item>
  </channel>
</rss>

