<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DMZ to inside LAN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148531#M49591</link>
    <description>&lt;P&gt;As everyone has mentioned, if the hosts are communicating on their connected internal addresses all is good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I suspect you may be referring the the case where internal hosts get DNS entries with the external address of the servers in your DMZ. &amp;nbsp;Then you do need to use what is called "U turn" NAT for the connections to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See this documentation.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Configure-U-Turn-NAT/ta-p/65081" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Configure-U-Turn-NAT/ta-p/65081&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Mar 2017 00:00:18 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2017-03-21T00:00:18Z</dc:date>
    <item>
      <title>DMZ to inside LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148412#M49578</link>
      <description>&lt;P&gt;I know you need a security policy to go from dmz to Lan but do you need a nat statement. &amp;nbsp;On all the Palo Alto documents that I have seen no nat rule is used. &amp;nbsp;If I am wrong could some one send me a link. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 16:26:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148412#M49578</guid>
      <dc:creator>Andy_Hoeller</dc:creator>
      <dc:date>2017-03-20T16:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ to inside LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148420#M49579</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It all depends if you want to "hide" the source ip&amp;nbsp;or/and &amp;nbsp;if you coming&amp;nbsp;from the private ip address to the&amp;nbsp;public or vice versa. from DMZ to LAN (assuming you do have a private ip address range), if you want to "hide" the DMZ server source &amp;nbsp;ip address then you can NATed to the PA LAN interface so all request will appear for the LAN users as PA source ip.&amp;nbsp;NAT is not a requirement&amp;nbsp;between the&amp;nbsp;rfc 1918 ip addresses but it is between&amp;nbsp;the public ip&amp;nbsp;as private ip are not allowed on Internet.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 17:21:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148420#M49579</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-20T17:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ to inside LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148428#M49580</link>
      <description>&lt;P&gt;Can you explain what you are trying to do a little bit more, and what your current infrastructure looks like. You may be thinking about a u-turn NAT or hairpinning but without knowing what your setup looks like we can't give you an answer for your enviroment.&lt;/P&gt;&lt;P&gt;Generally the respective zones would just need security policies put into place to allow the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 17:31:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148428#M49580</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-20T17:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ to inside LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148434#M49581</link>
      <description>&lt;P&gt;no, DMZ &amp;lt;-&amp;gt; Trust should not require a NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As long as the routing is all square, you won't need anything beyond the security policy. With or without the policy in place, the traffic logs should confirm that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 18:19:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148434#M49581</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-20T18:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ to inside LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148443#M49582</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 18:57:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148443#M49582</guid>
      <dc:creator>Andy_Hoeller</dc:creator>
      <dc:date>2017-03-20T18:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ to inside LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148531#M49591</link>
      <description>&lt;P&gt;As everyone has mentioned, if the hosts are communicating on their connected internal addresses all is good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I suspect you may be referring the the case where internal hosts get DNS entries with the external address of the servers in your DMZ. &amp;nbsp;Then you do need to use what is called "U turn" NAT for the connections to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See this documentation.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Configure-U-Turn-NAT/ta-p/65081" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Configure-U-Turn-NAT/ta-p/65081&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2017 00:00:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/148531#M49591</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-03-21T00:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ to inside LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/149967#M49858</link>
      <description>&lt;P&gt;thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 16:40:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-to-inside-lan/m-p/149967#M49858</guid>
      <dc:creator>Andy_Hoeller</dc:creator>
      <dc:date>2017-03-28T16:40:37Z</dc:date>
    </item>
  </channel>
</rss>

