<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security policy and NAT -  zone direction in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/122284#M46129</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any one?&lt;/P&gt;</description>
    <pubDate>Sat, 29 Oct 2016 15:23:25 GMT</pubDate>
    <dc:creator>ghostrider</dc:creator>
    <dc:date>2016-10-29T15:23:25Z</dc:date>
    <item>
      <title>Security policy and NAT -  zone direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/122057#M46100</link>
      <description>&lt;P&gt;Hello Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I confiugre the NAT and associated security policy then I always confuse about the direction of zones. As I understand NAT zones are always determined by ingress interface zone (source zone) and route lookup gives the outoing interface zone (destination zone) but my question is when we confiugre the associated security policy then zones direction would be post-nat address zones or pre-nat address zones?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2016 13:57:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/122057#M46100</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-28T13:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy and NAT -  zone direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/122284#M46129</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any one?&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2016 15:23:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/122284#M46129</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-29T15:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy and NAT -  zone direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/122843#M46185</link>
      <description>&lt;P&gt;Hi...The security rule is post-NAT so you should use the zones where the actual client/server lives. &amp;nbsp;Here's a NAT doc for reference:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Understanding-PAN-OS-NAT/ta-p/60965?attachment-id=1707" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Understanding-PAN-OS-NAT/ta-p/60965?attachment-id=1707&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way I use to remember which zone to use for NAT is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- write the security &amp;amp; NAT rule using the zones where the client &amp;amp; server actually live.&lt;/P&gt;&lt;P&gt;- If this is a dest NAT, then use the zone of the actual client as the source &amp;amp; dest zones in the NAT rule only, not security rule. &amp;nbsp;Security rule will stay the same as described in previous step&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2016 14:51:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/122843#M46185</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-11-01T14:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy and NAT -  zone direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/122847#M46186</link>
      <description>&lt;P&gt;This video helped me to understood the NAT config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=aVXzzZEgIA4" target="_blank"&gt;https://www.youtube.com/watch?v=aVXzzZEgIA4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2016 15:39:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/122847#M46186</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-01T15:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy and NAT -  zone direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/124346#M46300</link>
      <description>&lt;P&gt;thanks But I am not able to understand that destination NAT happens before security policy so in security policy, we should use the post-nated address (private address) but we use the original public address?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Nov 2016 19:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-and-nat-zone-direction/m-p/124346#M46300</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-05T19:04:15Z</dc:date>
    </item>
  </channel>
</rss>

