<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT configuration - DMZ zone to Trust zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-dmz-zone-to-trust-zone/m-p/160320#M52281</link>
    <description>&lt;P&gt;I've had a total brain fade, and am unable to figure this out. Hoping you guys can help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network topology is relatively simple. Firewall has three zones - outside, inside and DMZ - DMZ has a /25 of "real" Internet addresses on it. Outside has a /30, also of "real" address, and most traffic from inside is translated to the interface address of the outside zone. Inside if RFC1918 IPv4 addressing with multiple static routes to upstream networks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to NAT an IP address which is in our public space in our DMZ zone - call the address 1.1.1.123/32 - to a host which is inside my network - call it 10.10.10.10/32 - on a one-to-one basis - no port translations, nothing. BI-directional NAT - any packet coming in to 1.1.1.123 goes to 10.10.10.10, and any packet going OUT from 10.10.10.10 appears to be from 1.1.1.123 as far as the Internet is concerned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thing is, I don't know if I can do this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've put in two NAT rules - one translating anything going to 1.1.1.123 to 10.10.10.10, and one translating anything from 10.10.10.10 to 1.1.1.123 - but it's not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if I'm screwing up the security policies related, or if what I'm asking can't be done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, questions for guys who have done more NAT than I have&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Is the NAT policy I want even possible?&lt;/P&gt;&lt;P&gt;2. Is the methodoligy I've described right?&lt;/P&gt;&lt;P&gt;3. What IP address/interface should I be applying security policies (inbound and outbound) on? The translated address? The untranslated address? Both?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone shed some light for me, please? I'm scratching my head here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jun 2017 00:24:09 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2017-06-09T00:24:09Z</dc:date>
    <item>
      <title>NAT configuration - DMZ zone to Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-dmz-zone-to-trust-zone/m-p/160320#M52281</link>
      <description>&lt;P&gt;I've had a total brain fade, and am unable to figure this out. Hoping you guys can help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network topology is relatively simple. Firewall has three zones - outside, inside and DMZ - DMZ has a /25 of "real" Internet addresses on it. Outside has a /30, also of "real" address, and most traffic from inside is translated to the interface address of the outside zone. Inside if RFC1918 IPv4 addressing with multiple static routes to upstream networks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to NAT an IP address which is in our public space in our DMZ zone - call the address 1.1.1.123/32 - to a host which is inside my network - call it 10.10.10.10/32 - on a one-to-one basis - no port translations, nothing. BI-directional NAT - any packet coming in to 1.1.1.123 goes to 10.10.10.10, and any packet going OUT from 10.10.10.10 appears to be from 1.1.1.123 as far as the Internet is concerned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thing is, I don't know if I can do this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've put in two NAT rules - one translating anything going to 1.1.1.123 to 10.10.10.10, and one translating anything from 10.10.10.10 to 1.1.1.123 - but it's not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if I'm screwing up the security policies related, or if what I'm asking can't be done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, questions for guys who have done more NAT than I have&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Is the NAT policy I want even possible?&lt;/P&gt;&lt;P&gt;2. Is the methodoligy I've described right?&lt;/P&gt;&lt;P&gt;3. What IP address/interface should I be applying security policies (inbound and outbound) on? The translated address? The untranslated address? Both?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone shed some light for me, please? I'm scratching my head here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 00:24:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-dmz-zone-to-trust-zone/m-p/160320#M52281</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2017-06-09T00:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT configuration - DMZ zone to Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-dmz-zone-to-trust-zone/m-p/160330#M52283</link>
      <description>&lt;P&gt;Hey Darren,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try the below?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#808000"&gt;Outbound Nat rule&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;==============&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original packet:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Source - Trust&lt;/LI&gt;&lt;LI&gt;Source address - 10.10.10.10&lt;/LI&gt;&lt;LI&gt;Destination - Untrust&lt;/LI&gt;&lt;LI&gt;Destination Address - Any&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Translated packet:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Source translation - Static IP&lt;/LI&gt;&lt;LI&gt;Translated address - 1.1.1.123&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#808000"&gt;Inbound NAT rule&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;==============&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original packet:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Source - Untrust&lt;/LI&gt;&lt;LI&gt;Source address - Any&lt;/LI&gt;&lt;LI&gt;Destination - DMZ (you got public connectivity to DMZ, right?)&lt;/LI&gt;&lt;LI&gt;Destination Address - 1.1.1.123&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Translated packet:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Destination translation&lt;/LI&gt;&lt;LI&gt;Translated address - 10.10.10.10&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#0000FF"&gt;Outbound Security Rule&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;==================&lt;/P&gt;&lt;P&gt;Source Zone - Trust&lt;/P&gt;&lt;P&gt;Source Address - 10.10.10.10&lt;/P&gt;&lt;P&gt;Destination zone - Untrust&lt;/P&gt;&lt;P&gt;Destination address - Any&lt;/P&gt;&lt;P&gt;... (fill the rest yourself)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#0000FF"&gt;Inbound Security Rule&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;==================&lt;/P&gt;&lt;P&gt;Source Zone - Untrust&lt;/P&gt;&lt;P&gt;Source Address - Any&lt;/P&gt;&lt;P&gt;Destination zone - Trust&lt;/P&gt;&lt;P&gt;Destination Address - 1.1.1.123&lt;/P&gt;&lt;P&gt;... (fill the rest yourself)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For testing purposes, keep your NAT &amp;amp; security rules at the top to avoid any conflicts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if that works.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 00:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-dmz-zone-to-trust-zone/m-p/160330#M52283</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-06-09T00:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT configuration - DMZ zone to Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-dmz-zone-to-trust-zone/m-p/160347#M52286</link>
      <description>&lt;P&gt;Thank you Sir, you are a legend.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was applying the inbound security rule on the wrong zone, and everything was failing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now it's not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate your assistance.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 03:12:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-dmz-zone-to-trust-zone/m-p/160347#M52286</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2017-06-09T03:12:49Z</dc:date>
    </item>
  </channel>
</rss>

