<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HA binding &amp;quot;both option&amp;quot; not working in NAT policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-binding-quot-both-option-quot-not-working-in-nat-policy/m-p/6061#M4402</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured my Palo Alto Cluster in a L3 Active / Active cluster setup.&lt;/P&gt;&lt;P&gt;While I was trying to implement a NAT policy (Source Address Translation), it turns out that the only options that are working are: "0" and "1", as a reference to the member of the active/active cluster which should take care of the Address Translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It turns out that the other option are not accepted by the PAN-OS while trying to push/commit the previously defined NAT policy (results in ERROR)&lt;/P&gt;&lt;P&gt;&lt;IMG alt="SnipImage.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8747_SnipImage.JPG.jpg" style="width: 620px; height: 169px;" /&gt;&lt;/P&gt;&lt;P&gt;Would be works as designed?&lt;/P&gt;&lt;P&gt;Because, as a workaround I cloned the NAT rule, using either active/active binding to "0"&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;the exact same NAT rule, using active/active binding "1".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to be working fine, although I can imaging that the option "PRIMARY" would allow us to create this NAT rule ONLY ONCE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Wim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Oct 2013 20:03:09 GMT</pubDate>
    <dc:creator>wimjuste</dc:creator>
    <dc:date>2013-10-01T20:03:09Z</dc:date>
    <item>
      <title>HA binding "both option" not working in NAT policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-binding-quot-both-option-quot-not-working-in-nat-policy/m-p/6061#M4402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured my Palo Alto Cluster in a L3 Active / Active cluster setup.&lt;/P&gt;&lt;P&gt;While I was trying to implement a NAT policy (Source Address Translation), it turns out that the only options that are working are: "0" and "1", as a reference to the member of the active/active cluster which should take care of the Address Translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It turns out that the other option are not accepted by the PAN-OS while trying to push/commit the previously defined NAT policy (results in ERROR)&lt;/P&gt;&lt;P&gt;&lt;IMG alt="SnipImage.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8747_SnipImage.JPG.jpg" style="width: 620px; height: 169px;" /&gt;&lt;/P&gt;&lt;P&gt;Would be works as designed?&lt;/P&gt;&lt;P&gt;Because, as a workaround I cloned the NAT rule, using either active/active binding to "0"&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;the exact same NAT rule, using active/active binding "1".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to be working fine, although I can imaging that the option "PRIMARY" would allow us to create this NAT rule ONLY ONCE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Wim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Oct 2013 20:03:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-binding-quot-both-option-quot-not-working-in-nat-policy/m-p/6061#M4402</guid>
      <dc:creator>wimjuste</dc:creator>
      <dc:date>2013-10-01T20:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: HA binding "both option" not working in NAT policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-binding-quot-both-option-quot-not-working-in-nat-policy/m-p/6062#M4403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In a A/A cluster, each device requires its own IP pool and is associated to a device-id. Hence for source translation, you will need two rules using the corresponding device-id, so w&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;hen a new session is created, device binding &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;determines which NAT rules are matched by the firewall (the device binding must include the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;session owner device to produce a match).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer to pages 25, 96 &amp;amp; 97 in the following article for more on NAT in A/A setup:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2541"&gt;Configuring Active/Active HA PAN-OS 4.0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aditi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 03:03:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-binding-quot-both-option-quot-not-working-in-nat-policy/m-p/6062#M4403</guid>
      <dc:creator>apasupulati</dc:creator>
      <dc:date>2013-10-07T03:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: HA binding "both option" not working in NAT policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-binding-quot-both-option-quot-not-working-in-nat-policy/m-p/6063#M4404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Meanwhile I also received feedback of our Palo Alto Networks local systems engineer.&lt;/P&gt;&lt;P&gt;Allow me to share this information, because it revealed to root cause / answer to our problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;&lt;EM&gt;NAT device binding options include the following:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;Device 0 and Device 1—Translation is performed according to device-specific bindings &lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;only if the session owner and the device ID in the NAT rule match. evice-specific NAT &lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;rules are commonly used when the two firewalls use unique public IP addresses for &lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;translation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Both—This option allows either device to match new sessions to the NAT rule and is commonly used for destination NAT&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Primary—This option allows only the active-primary device to match new sessions to the &lt;/EM&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;&lt;EM&gt;NAT rule. This setting is used mainly for inbound static NAT, where only one firewall &lt;/EM&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;&lt;EM&gt;should respond to ARP requests. Unlike device 0/1 bindings, a primary device binding can move between devices when the primary role is transferred&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 08:22:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-binding-quot-both-option-quot-not-working-in-nat-policy/m-p/6063#M4404</guid>
      <dc:creator>wimjuste</dc:creator>
      <dc:date>2013-10-11T08:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: HA binding "both option" not working in NAT policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-binding-quot-both-option-quot-not-working-in-nat-policy/m-p/6064#M4405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can someone clarify for me the setup for a "dynamic-ip-and-port" source nat on an active/active cluster?&amp;nbsp; The traffic for this particular rule must be source natted to a particular x.x.2.15 address when traversing through either device and should work when either member is down.&amp;nbsp; Please specify the A/A bindings required for the rule, and scenarios with and without floating IPs on the outside. Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Johnny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2014 20:29:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-binding-quot-both-option-quot-not-working-in-nat-policy/m-p/6064#M4405</guid>
      <dc:creator>Rjschultz</dc:creator>
      <dc:date>2014-05-19T20:29:28Z</dc:date>
    </item>
  </channel>
</rss>

