<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure NAT for untagged subinterfaces? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-nat-for-untagged-subinterfaces/m-p/77872#M42736</link>
    <description>&lt;P&gt;HI&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have exact same scenario, but rather than doing the NAT with the ip address of the interface, we need to nat with 1 of the ip address which is the same range with FW sub interface (untagg).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What we are trying to do is PA firewall running multiple VSYS, each VSYS will share one physical interface with multiple untagg subinterfaces, and each VSYS to get 1 public ip each from the same range. Also some of the extra remaining public IP address we need to perform 1 to 1 NAT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1 to 1 NAT works fine when public ip address is configured on main interface of fw with untag, NAT doesn't work anymore when we move public ip to sub interface(untagg). However, communication from multiple VSYS with untag sub interface still can communicate with outside world via ip address assigned on untag sub interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please could you help ? Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 10 May 2016 21:48:45 GMT</pubDate>
    <dc:creator>sailwinthu</dc:creator>
    <dc:date>2016-05-10T21:48:45Z</dc:date>
    <item>
      <title>How to configure NAT for untagged subinterfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-nat-for-untagged-subinterfaces/m-p/48062#M35345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to set up a fairly simple configuration where we have our separate wired and wireless networks connecting to the internet via one shared interface eth1/1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, I am attempting to replicate the configuration here &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1884"&gt;https://live.paloaltonetworks.com/docs/DOC-1884&lt;/A&gt; (but with only 2 local networks, not 3). This document stresses that explicit NAT rules must be set up, but does not give an example on how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set up untagged sub interfaces, the virtual routers, policies and what I believe to be the correct NAT policies. I know these are correct because if I only set up one sub interface everything is OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon as I set up a second subinterface and hook it up to the virtual router, traffic stops flowing. &lt;STRONG&gt;I am assuming that is because I have not created the NAT policy correctly&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please can somebody provide an example NAT policy for an untagged subinterface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2012 13:20:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-nat-for-untagged-subinterfaces/m-p/48062#M35345</guid>
      <dc:creator>CATSatIDS</dc:creator>
      <dc:date>2012-07-16T13:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure NAT for untagged subinterfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-nat-for-untagged-subinterfaces/m-p/48063#M35346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri','sans-serif'; color: black;"&gt;Without source NAT, untagged subinterfaces will not work.&amp;nbsp; We have to map traffic to a particular zone/vsys based on the destination of that packet (it must match a subinterface IP address).&amp;nbsp; Please refer to following doc in order to configure right NAT rules for untagged subinterfaces. Please let us know if that helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2781"&gt;https://live.paloaltonetworks.com/docs/DOC-2781&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2012 00:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-nat-for-untagged-subinterfaces/m-p/48063#M35346</guid>
      <dc:creator>snisar</dc:creator>
      <dc:date>2012-09-13T00:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure NAT for untagged subinterfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-nat-for-untagged-subinterfaces/m-p/77872#M42736</link>
      <description>&lt;P&gt;HI&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have exact same scenario, but rather than doing the NAT with the ip address of the interface, we need to nat with 1 of the ip address which is the same range with FW sub interface (untagg).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What we are trying to do is PA firewall running multiple VSYS, each VSYS will share one physical interface with multiple untagg subinterfaces, and each VSYS to get 1 public ip each from the same range. Also some of the extra remaining public IP address we need to perform 1 to 1 NAT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1 to 1 NAT works fine when public ip address is configured on main interface of fw with untag, NAT doesn't work anymore when we move public ip to sub interface(untagg). However, communication from multiple VSYS with untag sub interface still can communicate with outside world via ip address assigned on untag sub interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please could you help ? Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2016 21:48:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-nat-for-untagged-subinterfaces/m-p/77872#M42736</guid>
      <dc:creator>sailwinthu</dc:creator>
      <dc:date>2016-05-10T21:48:45Z</dc:date>
    </item>
  </channel>
</rss>

