<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RDP NAT connection issue? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155003#M51000</link>
    <description>&lt;P&gt;I disagree.&lt;/P&gt;&lt;P&gt;Your Security Policy does NOT need to include internal IP.&lt;/P&gt;&lt;P&gt;As first is done NAT evaluation. This will tell firewall where packet needs to go to.&lt;/P&gt;&lt;P&gt;Then security policy is checked.&lt;/P&gt;&lt;P&gt;And last NAT is applied - just before packet is sent out to wire.&lt;/P&gt;&lt;P&gt;So security policy is checked when packet still has original IP but destination zone has already been changed in packet metadata.&lt;/P&gt;</description>
    <pubDate>Wed, 03 May 2017 14:27:45 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2017-05-03T14:27:45Z</dc:date>
    <item>
      <title>RDP NAT connection issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/154978#M50992</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For test purposes, I am trying to get RDP to work going through my PA-200 OS 6.1.4 to an internal PC.&lt;/P&gt;&lt;P&gt;I've been following several articles like this one, but not getting it to work.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/MS-RDP-NAT-Issue/m-p/15217/thread-id/11171/highlight/true" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/MS-RDP-NAT-Issue/m-p/15217/thread-id/11171/highlight/true&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I must be doing something wrong since my internet access&amp;nbsp;rules are working fine.&lt;/P&gt;&lt;P&gt;Anyone see anything in my rules that look wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RDPNAT.jpg" style="width: 764px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9028i76A8D4881745C260/image-dimensions/764x172/is-moderation-mode/true?v=v2" width="764" height="172" role="button" title="RDPNAT.jpg" alt="RDPNAT.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RDPsecurity.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9031iEEBA81D534545642/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="RDPsecurity.jpg" alt="RDPsecurity.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 11:58:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/154978#M50992</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-05-03T11:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: RDP NAT connection issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155000#M50998</link>
      <description>&lt;P&gt;Hey your second line shows your IP so no reason to hide it in first one.&lt;/P&gt;&lt;P&gt;NAT screenshot does not show right column that should include RDP server internal ip. So can't validate if this is there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other thing you can try is to enable bi-directional checkbox on second NAT rule. This will do the trick also create hidden NAT rule for incoming RDP traffic).&lt;/P&gt;&lt;P&gt;Hidden NAT policy is visible in CLI "show running nat-policy"&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 13:43:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155000#M50998</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-03T13:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: RDP NAT connection issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155001#M50999</link>
      <description>&lt;P&gt;--- removed&amp;nbsp; ---&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 14:48:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155001#M50999</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-05-03T14:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: RDP NAT connection issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155003#M51000</link>
      <description>&lt;P&gt;I disagree.&lt;/P&gt;&lt;P&gt;Your Security Policy does NOT need to include internal IP.&lt;/P&gt;&lt;P&gt;As first is done NAT evaluation. This will tell firewall where packet needs to go to.&lt;/P&gt;&lt;P&gt;Then security policy is checked.&lt;/P&gt;&lt;P&gt;And last NAT is applied - just before packet is sent out to wire.&lt;/P&gt;&lt;P&gt;So security policy is checked when packet still has original IP but destination zone has already been changed in packet metadata.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 14:27:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155003#M51000</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-03T14:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: RDP NAT connection issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155004#M51001</link>
      <description>&lt;P&gt;In my experience Raido is correct.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 14:40:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155004#M51001</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-03T14:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: RDP NAT connection issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155013#M51003</link>
      <description>&lt;P&gt;you are correct. I completely reversed the policies. I confused myself. apologies.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 14:49:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155013#M51003</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-05-03T14:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: RDP NAT connection issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155016#M51006</link>
      <description>&lt;P&gt;Thanks folks!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will follow up and update this post later this evening.&lt;/P&gt;&lt;P&gt;This is my diagram trying to accomplish.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RDPdiag.jpg" style="width: 722px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9042i4088E43C379B256D/image-dimensions/722x111/is-moderation-mode/true?v=v2" width="722" height="111" role="button" title="RDPdiag.jpg" alt="RDPdiag.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 16:42:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155016#M51006</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-05-03T16:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: RDP NAT connection issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155113#M51026</link>
      <description>&lt;P&gt;Ok, got it!&amp;nbsp; Thank you for the feedback!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I forgot to adjust my gateway on internal server.&amp;nbsp; Also do not need a bi-directional NAT rule.&amp;nbsp; Just D-NAT and Internet S-NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the record, my correct rules below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RDPsuccess1.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9057i7987C0D950459589/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="RDPsuccess1.jpg" alt="RDPsuccess1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RDPsuccess2.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9058iD9621DF6F5FF087E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="RDPsuccess2.jpg" alt="RDPsuccess2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 10:16:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-nat-connection-issue/m-p/155113#M51026</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-05-04T10:16:05Z</dc:date>
    </item>
  </channel>
</rss>

