<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Expressway-E and C and NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/158167#M51785</link>
    <description>&lt;P&gt;I am putting in a Jabber system using Expressway-E and C. My Expressway-E server is NAT'd through the PA-3020 and I have a security rule set up to allow the required ports in on the Public address. If I make a call IN from an external Jabber client it goes through fine. If I try to make a call OUT from a phone to a jabber client, the call does not go through.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My setup is similar to this:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.1.10 (internal address of EXP-E)&lt;/P&gt;&lt;P&gt;210.1.2.1 (external IP of EXP-E)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.1.10 is NAT'd through to 210.1.2.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;u_turn rule&amp;nbsp;&lt;/P&gt;&lt;P&gt;trust-&amp;gt; untrust Dest Address=210.1.2.1 &amp;nbsp;Source Translation= Dynamic/210.1.2.1 destination translation =192.168.1.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MIp_rule&lt;/P&gt;&lt;P&gt;trust-&amp;gt;untrust source address=192.168.1.10 &amp;nbsp;source translation static/210.1.2.1 bi-di.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security rule set up to allow incoming SIP type ports to come across on the 210.1.2.1 external IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Expressway E is set up with a single interface. When Expressway-E has NAT turned on, I can make a call from external to internal. WHen Expressway-E has NAT turned off, I CAN get a call to go external, but there is no audio.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any idea what I am doing wrong?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2017 21:06:47 GMT</pubDate>
    <dc:creator>EricPortenier</dc:creator>
    <dc:date>2017-05-24T21:06:47Z</dc:date>
    <item>
      <title>Expressway-E and C and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/158167#M51785</link>
      <description>&lt;P&gt;I am putting in a Jabber system using Expressway-E and C. My Expressway-E server is NAT'd through the PA-3020 and I have a security rule set up to allow the required ports in on the Public address. If I make a call IN from an external Jabber client it goes through fine. If I try to make a call OUT from a phone to a jabber client, the call does not go through.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My setup is similar to this:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.1.10 (internal address of EXP-E)&lt;/P&gt;&lt;P&gt;210.1.2.1 (external IP of EXP-E)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.1.10 is NAT'd through to 210.1.2.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;u_turn rule&amp;nbsp;&lt;/P&gt;&lt;P&gt;trust-&amp;gt; untrust Dest Address=210.1.2.1 &amp;nbsp;Source Translation= Dynamic/210.1.2.1 destination translation =192.168.1.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MIp_rule&lt;/P&gt;&lt;P&gt;trust-&amp;gt;untrust source address=192.168.1.10 &amp;nbsp;source translation static/210.1.2.1 bi-di.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security rule set up to allow incoming SIP type ports to come across on the 210.1.2.1 external IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Expressway E is set up with a single interface. When Expressway-E has NAT turned on, I can make a call from external to internal. WHen Expressway-E has NAT turned off, I CAN get a call to go external, but there is no audio.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any idea what I am doing wrong?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 21:06:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/158167#M51785</guid>
      <dc:creator>EricPortenier</dc:creator>
      <dc:date>2017-05-24T21:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Expressway-E and C and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/158207#M51792</link>
      <description>&lt;P&gt;Hi Eric,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Welcome to the community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kinda hard to guess what's going on with the traffic. Can you check the session on the CLI when testing? - show session all filter source x.x.x.x&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, pcaps would be insightful in this scenario (&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 23:26:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/158207#M51792</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-05-24T23:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Expressway-E and C and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/158884#M52035</link>
      <description>&lt;P&gt;What we found out was that Expressway needs to be configured in a dual nic configuration - one internal NIC and one External NIC. Trying to get it working on a single NIC with NAT through a PA will apparently not work. I also had to create a non-routable (internally) vLAN and use it on a DMZ port on the Palo ALto. I then took the Expressway interface configured for External access and put it on the DMZ vLAN. That Expressway NIC was configured with internal NAT, a security rule and direct NAT rule were created on the Palo Alto, and all worked afterward. I guess the real hold up was that a DMZ needed to be created on the PA (we didn't really have one prior to this) and the Expressway needed to be set to use dual interfaces. Once everything was&amp;nbsp;configured and secured properly, we were able to register external SIP phones and make and receive calls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 14:46:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/158884#M52035</guid>
      <dc:creator>EricPortenier</dc:creator>
      <dc:date>2017-06-01T14:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Expressway-E and C and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/320822#M82130</link>
      <description>&lt;P&gt;This is an old post, but I'm doing the same thing with Jabber and a single Palo Alto firewall. Dual NIC Expressway configuration. Are you by chance still doing all this and be willing to send over your NAT and security rules that are set up? Static NAT on the external Expressway-E interface out to a public address is no problem. I get all that. I'm still trying to get my head around what needs to happen between the Expressway-C and Expressway-E internal and external interfaces.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 01:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/320822#M82130</guid>
      <dc:creator>adam.b</dc:creator>
      <dc:date>2020-04-06T01:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Expressway-E and C and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/352183#M87148</link>
      <description>&lt;P&gt;I am in the same boat - wanted to verify my configuration -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a NAT&lt;/P&gt;&lt;P&gt;Source Zone - untrust &amp;gt; Destination Zone - untrust &amp;gt; Destination address - Public expressway E &amp;gt; Destination Translation - address - DMZ-express E&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source zone - untrust &amp;gt; Destination zone - DMZ &amp;gt; Destination address - Public expressway E &amp;gt; service - ports for expressway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that sound right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 16:36:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/352183#M87148</guid>
      <dc:creator>lsimanek</dc:creator>
      <dc:date>2020-09-25T16:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Expressway-E and C and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/352445#M87191</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1117"&gt;@lsimanek&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're facing kind of issues with the below configuration, try with &lt;EM&gt;&lt;STRONG&gt;Static Bidirectional NAT&amp;nbsp; &lt;/STRONG&gt;&lt;/EM&gt;configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 06:46:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expressway-e-and-c-and-nat/m-p/352445#M87191</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-09-28T06:46:20Z</dc:date>
    </item>
  </channel>
</rss>

