<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Natting issue with new subnet. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/natting-issue-with-new-subnet/m-p/141806#M48447</link>
    <description>&lt;P&gt;I am applying destination nat. Natting public ip(untrust zone) to internal ip(trust zone). Public ip subnet is /28.&lt;/P&gt;&lt;P&gt;When access public ip in the monitoring logs it shows me dst zone as Untrust whenit should show dst zone as Trust.&lt;/P&gt;&lt;P&gt;I have policy in place and natting but its not hitting any policy and goes to expicit deny.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Feb 2017 05:04:18 GMT</pubDate>
    <dc:creator>inderjit21</dc:creator>
    <dc:date>2017-02-08T05:04:18Z</dc:date>
    <item>
      <title>Natting issue with new subnet.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-issue-with-new-subnet/m-p/141806#M48447</link>
      <description>&lt;P&gt;I am applying destination nat. Natting public ip(untrust zone) to internal ip(trust zone). Public ip subnet is /28.&lt;/P&gt;&lt;P&gt;When access public ip in the monitoring logs it shows me dst zone as Untrust whenit should show dst zone as Trust.&lt;/P&gt;&lt;P&gt;I have policy in place and natting but its not hitting any policy and goes to expicit deny.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 05:04:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-issue-with-new-subnet/m-p/141806#M48447</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2017-02-08T05:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Natting issue with new subnet.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-issue-with-new-subnet/m-p/141820#M48448</link>
      <description>&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Hi there,&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Did you apply the appropriate security policies and NAT policies in place for destination NAT?&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Generally there are 2 places to check in your configurations:&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;NAT Policy:&lt;/P&gt;&lt;P class="p1"&gt;Destination zone : Pre-NAT IP&lt;/P&gt;&lt;P class="p1"&gt;Destination address : Pre-NAT IP&lt;/P&gt;&lt;P class="p1"&gt;Destination Translation : Post-NAT IP&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Security Policy&lt;/P&gt;&lt;P class="p1"&gt;Destination zone : Post-NAT&lt;/P&gt;&lt;P class="p1"&gt;Destination address : Pre-NAT&lt;/P&gt;&lt;P class="p1"&gt;Source zone : Pre-NAT&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;I attached an illustration of diagram below for your reference. Hope it clarifies your understanding of destination NAT&lt;/P&gt;&lt;P class="p2"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="destination NAT diagram.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7696i0B7228ED3914A08C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="destination NAT diagram.png" alt="destination NAT diagram.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="destination NAT configuration.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7697iFC00CFCDE395887A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="destination NAT configuration.png" alt="destination NAT configuration.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 07:21:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-issue-with-new-subnet/m-p/141820#M48448</guid>
      <dc:creator>jneo</dc:creator>
      <dc:date>2017-02-08T07:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Natting issue with new subnet.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-issue-with-new-subnet/m-p/141833#M48451</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55672"&gt;@jneo&lt;/a&gt;&amp;nbsp;very good explanation. I am also always sharing this video:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=aVXzzZEgIA4" target="_blank"&gt;https://www.youtube.com/watch?v=aVXzzZEgIA4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 09:03:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-issue-with-new-subnet/m-p/141833#M48451</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-08T09:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Natting issue with new subnet.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-issue-with-new-subnet/m-p/141868#M48455</link>
      <description>&lt;P&gt;I also like &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/21723"&gt;@RafisGaripov&lt;/a&gt;&amp;nbsp;PAN videos&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is part 2 of the above nat video &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=Qq_T9mcBAYk" target="_blank"&gt;https://www.youtube.com/watch?v=Qq_T9mcBAYk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 13:55:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-issue-with-new-subnet/m-p/141868#M48455</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-02-08T13:55:52Z</dc:date>
    </item>
  </channel>
</rss>

