<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Destination NAT vs Source NAT with Bi-directional option in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-vs-source-nat-with-bi-directional-option/m-p/138472#M47966</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for all the explanations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Jan 2017 02:32:09 GMT</pubDate>
    <dc:creator>harshaabba</dc:creator>
    <dc:date>2017-01-20T02:32:09Z</dc:date>
    <item>
      <title>Destination NAT vs Source NAT with Bi-directional option</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-vs-source-nat-with-bi-directional-option/m-p/137520#M47811</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In enterprise network, what are the usage scenarios for Destination NAT and Source NAT with Bi-directional option enable ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Harsha&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jan 2017 02:06:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-vs-source-nat-with-bi-directional-option/m-p/137520#M47811</guid>
      <dc:creator>harshaabba</dc:creator>
      <dc:date>2017-01-15T02:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT vs Source NAT with Bi-directional option</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-vs-source-nat-with-bi-directional-option/m-p/137543#M47812</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very good explanation here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/networking/nat-configuration-examples" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/networking/nat-configuration-examples&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=aVXzzZEgIA4" target="_blank"&gt;https://www.youtube.com/watch?v=aVXzzZEgIA4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doesn't&amp;nbsp;matter enterprise or home network NAT still the same:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source&amp;nbsp;NAT translates&amp;nbsp;your source&amp;nbsp;IP to a different one&lt;/P&gt;&lt;P&gt;Destination NAT translate your destination IP (one use of for&amp;nbsp;enabling access to your internal servers from Internet)&lt;/P&gt;&lt;P&gt;Bi-directional really same as above, means by ticking the&amp;nbsp;box you will create implicit Destination NAT policy. GUI will only show you that it is bidirectional&amp;nbsp;but CLI will display the same rule&amp;nbsp;as two separate (Source and Destination):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; show running nat-policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jan 2017 07:55:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-vs-source-nat-with-bi-directional-option/m-p/137543#M47812</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-15T07:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT vs Source NAT with Bi-directional option</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-vs-source-nat-with-bi-directional-option/m-p/137599#M47819</link>
      <description>&lt;P&gt;Here's a video where I explain several scenarios : &lt;A title="Tutorial: Network Address Translation " href="https://www.youtube.com/watch?v=zLqsSuOVzzU" target="_blank"&gt;Tutorial: Network Address Translation &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is only one configuration method allowed where the bi-directional option is supported, and that is for source nat (bi-directional cannot be enabled when destination NAT is configured because the bi-directional option needs to be able to set the destination option in the implied reverse policy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if for example the configured rule is like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bidirectional nat.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="bidirectional nat.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;the bi-directional option will create an implied rule that sets destination translation for IP 2.2.2.2 if the original packet is headed toward 10.0.0.1 coming from the remote zone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2017 08:50:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-vs-source-nat-with-bi-directional-option/m-p/137599#M47819</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-01-16T08:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Destination NAT vs Source NAT with Bi-directional option</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-vs-source-nat-with-bi-directional-option/m-p/138472#M47966</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for all the explanations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2017 02:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-nat-vs-source-nat-with-bi-directional-option/m-p/138472#M47966</guid>
      <dc:creator>harshaabba</dc:creator>
      <dc:date>2017-01-20T02:32:09Z</dc:date>
    </item>
  </channel>
</rss>

