<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Many-to-One Destination NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/many-to-one-destination-nat/m-p/78429#M42941</link>
    <description>&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have now configured multiple NAT rules for the domain controllers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="panos_screenshot_campusmsdcsuat2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4099i90A1F15D317D4E5F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="panos_screenshot_campusmsdcsuat2.png" alt="panos_screenshot_campusmsdcsuat2.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
    <pubDate>Fri, 20 May 2016 14:16:20 GMT</pubDate>
    <dc:creator>Gurminder</dc:creator>
    <dc:date>2016-05-20T14:16:20Z</dc:date>
    <item>
      <title>Many-to-One Destination NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/many-to-one-destination-nat/m-p/78414#M42934</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currently have a problem on site&amp;nbsp;where our windows domain name matches the website name so the naked domain DNS configuration contains an A record for a web server and not the domain controllers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a short term workaround (because it could take 2-3 years to plan and change the domain name) I'm using the destination NAT feature.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my testing this has proved to work successfully; Changing the A record to match a domain controller so domain connected machines have no problem contacting them and the NAT will take care of traffic going to HTTP and HTTPS and replacing the IP address with the web server. Rule below;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="panos_screenshot_campusmsdcsuat.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4096iC6F60FB173D8D55B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="panos_screenshot_campusmsdcsuat.png" alt="panos_screenshot_campusmsdcsuat.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem has come into place with more than one domain controller...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding another entry in the in the destionation address list throws the following error when commiting;&lt;/P&gt;&lt;P&gt;"Mismatch of destionation address translation range between original and translated address"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand it is trying to tell me I can only translate one-to-one when using destination NAT, but I'm wondering why? Could I just have 4 NAT rules for 4 domain controllers all doing the same thing? Or is this not best practice? Is there another way I could configure these devices for the desired effect?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 09:44:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/many-to-one-destination-nat/m-p/78414#M42934</guid>
      <dc:creator>Gurminder</dc:creator>
      <dc:date>2016-05-20T09:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Many-to-One Destination NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/many-to-one-destination-nat/m-p/78420#M42937</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT will try to apply your translation to a subnet, so a /32 will simply address 1 single host, but adding a secondary ip in there would logically be done by setting the subnet to /30 and translating to a /30 range. 2 or more independent (non-consecutive within the same subnet) destination NAT hosts would require a policy per host (so 4 policies, each containing a single destination subnet of /32, in your example)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-05-20_13-32-17.jpg"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="2016-05-20_13-32-17.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 11:32:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/many-to-one-destination-nat/m-p/78420#M42937</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-05-20T11:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: Many-to-One Destination NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/many-to-one-destination-nat/m-p/78429#M42941</link>
      <description>&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have now configured multiple NAT rules for the domain controllers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="panos_screenshot_campusmsdcsuat2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4099i90A1F15D317D4E5F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="panos_screenshot_campusmsdcsuat2.png" alt="panos_screenshot_campusmsdcsuat2.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 14:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/many-to-one-destination-nat/m-p/78429#M42941</guid>
      <dc:creator>Gurminder</dc:creator>
      <dc:date>2016-05-20T14:16:20Z</dc:date>
    </item>
  </channel>
</rss>

