<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What type of policy\rules do you need to access an internal licenses server from the internet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-type-of-policy-rules-do-you-need-to-access-an-internal/m-p/7146#M5278</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/14223"&gt;MemphisBrothers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Considering that the license server is in the dmz-L3 zone and the traffic is coming from the untrust-L3 zone, here is how you would go about creating service objects, NAT rule and security rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Service Objects (Source port kept empty):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="147" src="https://live.paloaltonetworks.com/legacyfs/online/9850_pastedImage_3.png" width="1340" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security Rule ( from untrust-L3 to dmz-L3):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="107" src="https://live.paloaltonetworks.com/legacyfs/online/9848_pastedImage_1.png" width="1354" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NAT Rule ( from untrust-L3 to untrust-L3):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="128" src="https://live.paloaltonetworks.com/legacyfs/online/9849_pastedImage_2.png" width="1345" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For future reference you refer the following document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;Understanding PAN-OS NAT&lt;/A&gt; (Page 19 -21 explains your scenario)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope the above configuration helps you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Nov 2013 19:32:18 GMT</pubDate>
    <dc:creator>kadak</dc:creator>
    <dc:date>2013-11-19T19:32:18Z</dc:date>
    <item>
      <title>What type of policy\rules do you need to access an internal licenses server from the internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-type-of-policy-rules-do-you-need-to-access-an-internal/m-p/7145#M5277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have an internal licenses server that users need to access from the internet, 10.1.3.21.&amp;nbsp; The The external exposed ip is 216.55.55.10&lt;/P&gt;&lt;P&gt;The application on the users computer needs the following TCP ports open through the firewall so that client workstations are able to obtain a license from your license server system.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;lmgrd.exe&lt;/STRONG&gt; needs INCOMING TCP ports 27000 to 27009 and &lt;STRONG&gt;adskflex.exe&lt;/STRONG&gt; needs 2080.&amp;nbsp; What is the easiest way to&amp;nbsp; address this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need a natting rule correct?&amp;nbsp; What type.&lt;/P&gt;&lt;P&gt;Once I figure out the natting rule then I can created policies to allow application traffic on the necessary ports.&amp;nbsp; Unless there is an exev simpler way to create it all.&amp;nbsp; Ideas welcome&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Nov 2013 02:43:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-type-of-policy-rules-do-you-need-to-access-an-internal/m-p/7145#M5277</guid>
      <dc:creator>MemphisBrothers</dc:creator>
      <dc:date>2013-11-19T02:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: What type of policy\rules do you need to access an internal licenses server from the internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-type-of-policy-rules-do-you-need-to-access-an-internal/m-p/7146#M5278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/14223"&gt;MemphisBrothers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Considering that the license server is in the dmz-L3 zone and the traffic is coming from the untrust-L3 zone, here is how you would go about creating service objects, NAT rule and security rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Service Objects (Source port kept empty):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="147" src="https://live.paloaltonetworks.com/legacyfs/online/9850_pastedImage_3.png" width="1340" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security Rule ( from untrust-L3 to dmz-L3):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="107" src="https://live.paloaltonetworks.com/legacyfs/online/9848_pastedImage_1.png" width="1354" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NAT Rule ( from untrust-L3 to untrust-L3):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="128" src="https://live.paloaltonetworks.com/legacyfs/online/9849_pastedImage_2.png" width="1345" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For future reference you refer the following document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;Understanding PAN-OS NAT&lt;/A&gt; (Page 19 -21 explains your scenario)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope the above configuration helps you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Nov 2013 19:32:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-type-of-policy-rules-do-you-need-to-access-an-internal/m-p/7146#M5278</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-19T19:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: What type of policy\rules do you need to access an internal licenses server from the internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-type-of-policy-rules-do-you-need-to-access-an-internal/m-p/7147#M5279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using this as a guide I was able to get what I needed to accomplish.&amp;nbsp; Thanks a lot.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 01:20:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-type-of-policy-rules-do-you-need-to-access-an-internal/m-p/7147#M5279</guid>
      <dc:creator>MemphisBrothers</dc:creator>
      <dc:date>2013-12-12T01:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: What type of policy\rules do you need to access an internal licenses server from the internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-type-of-policy-rules-do-you-need-to-access-an-internal/m-p/7148#M5280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;An addendum to this.&amp;nbsp; Turns out I only needed a rule for inbound traffic only.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 01:01:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-type-of-policy-rules-do-you-need-to-access-an-internal/m-p/7148#M5280</guid>
      <dc:creator>MemphisBrothers</dc:creator>
      <dc:date>2014-03-07T01:01:31Z</dc:date>
    </item>
  </channel>
</rss>

