<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Overlapping Subnets and NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/overlapping-subnets-and-nat/m-p/150046#M49873</link>
    <description>&lt;P&gt;Really trying to avoid having the customer setup something on their end, but yes it is a solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I dont think PBF will work as the lookup for the customer 10.10.0.0/16 will break connections to the internal 10.10.0.0/16 network.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Mar 2017 03:54:58 GMT</pubDate>
    <dc:creator>BrettBrown</dc:creator>
    <dc:date>2017-03-29T03:54:58Z</dc:date>
    <item>
      <title>Overlapping Subnets and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overlapping-subnets-and-nat/m-p/149815#M49837</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a new client we have a direct L3 link with. Our firewall has an existing directly connected interface on the 10.10.0.0/16 subnet. Our client also has a subnet of 10.10.0.0/16 which we need to get to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During my initial testing I decided just to access a /24 of the clients /16. I am natting the client subnet of 10.10.101.0/24 to 172.17.101.0/24.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a NAT policy with a source of another of my internal subnets (not the 10.10.0.0/16), destination of 172.17.101.0/24, source nat to a synamic ip+port, destination nat to 10.10.101.0/24.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the destination NAT kicks in it checks the source VR for its route which is the directly connected interface and attempts route it locally. If I remove the destination nat it&amp;nbsp;hits the destination interface but with the wrong destination address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Round 2:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I removed the customer config from the current VR and put them into a new VR, setup vr to vr routes. Same issue,&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the destination NAT kicks in it checks the source VR for its route which is the directly connected interface and attempts route it locally. If I remove the destination nat it&amp;nbsp;hits the destination interface but with the wrong destination address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how i can get around this without using a separate VSYS (i havent tried yet, not 100% sure it will work)?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 04:11:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overlapping-subnets-and-nat/m-p/149815#M49837</guid>
      <dc:creator>BrettBrown</dc:creator>
      <dc:date>2017-03-28T04:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping Subnets and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overlapping-subnets-and-nat/m-p/149901#M49848</link>
      <description>&lt;P&gt;is your customer capable of setting up NAT in their environment ?&lt;/P&gt;
&lt;P&gt;you could route 192.168.0.0/24 to their gateway and they could nat it to a /24 of their choice&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if there is a specific segment you need to be able to reach at their end you could use policy based forwarding as this redirects packets before they hit the routing table&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 12:17:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overlapping-subnets-and-nat/m-p/149901#M49848</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-28T12:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping Subnets and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overlapping-subnets-and-nat/m-p/150046#M49873</link>
      <description>&lt;P&gt;Really trying to avoid having the customer setup something on their end, but yes it is a solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I dont think PBF will work as the lookup for the customer 10.10.0.0/16 will break connections to the internal 10.10.0.0/16 network.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 03:54:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overlapping-subnets-and-nat/m-p/150046#M49873</guid>
      <dc:creator>BrettBrown</dc:creator>
      <dc:date>2017-03-29T03:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping Subnets and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overlapping-subnets-and-nat/m-p/150112#M49889</link>
      <description>&lt;P&gt;yeah PBF would only work for a select few ip's...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a very elaborate solution is to set up a second vsys with 2 interfaces (these can be subinterfaces)&lt;/P&gt;
&lt;P&gt;it would need an 'internal' interface connected to your dmz or untrust so you can easily route and NAT, on a subnet of 172.16.0.0/30 for example&lt;/P&gt;
&lt;P&gt;and an interface leading out to the customer's 10.10.0.0/16&lt;/P&gt;
&lt;P&gt;vsys2 would have static NAT set for 192.168.0.0/16 to 10.10.0.0/16 (this would perform a one to one nat, only replacing the first 2 bytes)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vsys1 would then simply need to have source nat to hide your 10.10 range behind the 172.16.0.0/30 IP and a route leading to the second vsys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 12:39:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overlapping-subnets-and-nat/m-p/150112#M49889</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-29T12:39:56Z</dc:date>
    </item>
  </channel>
</rss>

