<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: U-Turn NAT with Port Address Translation in a DMZ in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118462#M45630</link>
    <description>&lt;P&gt;Thanks Reaper! I originally had a VLAN and assigned it to the DMZ interface and it didnt work. I think I do have the servers and virtual router properly setup. Let me check these docs you sent over, delete the current config, and give it another go. Fingers crossed! Will advise shortly.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Oct 2016 15:27:39 GMT</pubDate>
    <dc:creator>vazquezr1</dc:creator>
    <dc:date>2016-10-07T15:27:39Z</dc:date>
    <item>
      <title>U-Turn NAT with Port Address Translation in a DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118301#M45621</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am configuring my first PA-200 and having a difficult time. I have a /27 external network and have the PA-200 seeing the internet properly. I have internet untrust zone setup as l3 on Int 1.1, and a DMZ setup as l3. The DMZ zone is on eth 1.2 interface and has a few servers plugged into an unmanaged gigabit belkin switch as depicted below. At this time, I am not planning to use the firewall with Trusted users or any of the other intefaces, just to serve up publically facing servers in the DMZ with specific ports. I have found several articles/config example suggesting that I use U-Turn Nat to make this happen properly but none that consider PAT as well along with layer2 traffic from the unmanaged switch. I was hoping someone could please provide some help. Thank you very much. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="DMZ Depiction PA-200.jpg" style="width: 516px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5810i8E14E3A084242E7F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DMZ Depiction PA-200.jpg" alt="DMZ Depiction PA-200.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 02:10:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118301#M45621</guid>
      <dc:creator>vazquezr1</dc:creator>
      <dc:date>2016-10-07T02:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: U-Turn NAT with Port Address Translation in a DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118390#M45626</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48304"&gt;@vazquezr1﻿&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you don't need u-turn nat to make this work (u-turn is used to reach internal servers, from the inside, on their external IP, you need regular inbound nat, with destination ports&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as it happens, i wrote a little something about that : &lt;A title="Getting Started: Network Address Translation " href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Network-Address-Translation/ta-p/116340" target="_blank"&gt;Getting Started: Network Address Translation &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;scroll down to 'Uni-directional policy', this should be the bit you need&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 09:10:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118390#M45626</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-10-07T09:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: U-Turn NAT with Port Address Translation in a DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118447#M45627</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate the help and article. I had actually started with your suggested config originally since that is what I remember from the (3) day training. I still couldnt see the servers from the outside. I remember somewhere that someone had said you had to "tag" layer 2 traffic of it was not routed from a managed switch? Since all these servers are sitting on a dumb hub basically perhaps that is the problem? I am just using the "default" virtual router but perhaps that is not sufficient. Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 15:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118447#M45627</guid>
      <dc:creator>vazquezr1</dc:creator>
      <dc:date>2016-10-07T15:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: U-Turn NAT with Port Address Translation in a DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118454#M45629</link>
      <description>&lt;P&gt;are your interfaces _sub_ interfaces ? i'm assuming they're normal L3 interfaces, in which case you don't need tags&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tags only come into play if you've got a managed switch connected to the firewall via a trunk interface (this causes the firewall to receive packets with the .1q header present, so you need to have tagged subinterfaces to diffeentiate between the vlan tags)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you make sure to set the nat rule&lt;/P&gt;
&lt;P&gt;from untrust to untrust, orig destination &amp;lt;external IP&amp;gt; destination translation &amp;lt;internal IP&amp;gt;&lt;/P&gt;
&lt;P&gt;and then &amp;nbsp;a security policy&lt;/P&gt;
&lt;P&gt;from untrust to trust, destination &amp;lt;external IP&amp;gt; apps, ports, allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you seeing the sessions in your traffic log ? (if not, the external router may not be aware you're there and you may need to check arp settings on the router for example)&lt;/P&gt;
&lt;P&gt;if you are, is the NAT represented as expected ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you did set a default gateway on your servers pointing to your firewall's DMZ IP, and a 0.0.0.0/0 route in the firewall VirtualRouter, pointing to the external router, right ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i got a whole bunch of articles that may be of interest &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;A title="Getting Started: The Series" href="https://live.paloaltonetworks.com/t5/Community-Blog/Getting-Started-The-Series/ba-p/67707" target="_blank"&gt;Getting Started: The Series&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 15:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118454#M45629</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-10-07T15:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: U-Turn NAT with Port Address Translation in a DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118462#M45630</link>
      <description>&lt;P&gt;Thanks Reaper! I originally had a VLAN and assigned it to the DMZ interface and it didnt work. I think I do have the servers and virtual router properly setup. Let me check these docs you sent over, delete the current config, and give it another go. Fingers crossed! Will advise shortly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 15:27:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/u-turn-nat-with-port-address-translation-in-a-dmz/m-p/118462#M45630</guid>
      <dc:creator>vazquezr1</dc:creator>
      <dc:date>2016-10-07T15:27:39Z</dc:date>
    </item>
  </channel>
</rss>

