<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route Public IP range through Shared Gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/route-public-ip-range-through-shared-gateway/m-p/165059#M53131</link>
    <description>&lt;P&gt;I would second the NAT option. &amp;nbsp;Setup a private subnet for each group of web servers (on their own zones) and then just NAT the traffic. &amp;nbsp;I would create a static by-directional NAT on the PA FW and then setup inbound Security Rules to only allow the inbound traffic to the servers on their proper protocol.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jul 2017 20:02:18 GMT</pubDate>
    <dc:creator>davanderson</dc:creator>
    <dc:date>2017-07-06T20:02:18Z</dc:date>
    <item>
      <title>Route Public IP range through Shared Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-public-ip-range-through-shared-gateway/m-p/164408#M53072</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you can lend me a hand here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our ISP finally allocated us a Public /25 (aa.bb.cc.0/25) subnet which will be routed via the&amp;nbsp;existing /30 (xx.yy.zz.2/30) internet link that we have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want to split it in half and use the Shared Gateway to route the traffic. The first half is for our webservers in VSYS1 . The other half is for office users who&amp;nbsp;are in VSYS2, which is where we also want our Global Protect to terminate on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Before I start breaking things apart)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q: Because we now have&amp;nbsp;public IPs, should i&amp;nbsp;continue to do all the NATs on the Shared Gteway,&amp;nbsp;OR can I now use each VSYS to do the NAT'ing? We prefer the latter, but I'm not sure what else will break of what else to consider going down this path&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2017 21:16:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-public-ip-range-through-shared-gateway/m-p/164408#M53072</guid>
      <dc:creator>SeboDeMacho</dc:creator>
      <dc:date>2017-07-03T21:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Route Public IP range through Shared Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-public-ip-range-through-shared-gateway/m-p/164579#M53078</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess having NATs in Shared gateway will be more appropriate. If you configure NAT on vsys, there will be routing considerations on the Shared gateway vsys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is an article for a bidirectional NAT involving shared gateway:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Configuring-Destination-NAT-using-a-VSYS-with-Shared-Gateway/ta-p/55187" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Configuring-Destination-NAT-using-a-VSYS-with-Shared-Gateway/ta-p/55187&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see if it helps. You can approach TAC if need any specific help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Abhishek&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 03:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-public-ip-range-through-shared-gateway/m-p/164579#M53078</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2017-07-05T03:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Route Public IP range through Shared Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-public-ip-range-through-shared-gateway/m-p/165059#M53131</link>
      <description>&lt;P&gt;I would second the NAT option. &amp;nbsp;Setup a private subnet for each group of web servers (on their own zones) and then just NAT the traffic. &amp;nbsp;I would create a static by-directional NAT on the PA FW and then setup inbound Security Rules to only allow the inbound traffic to the servers on their proper protocol.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 20:02:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-public-ip-range-through-shared-gateway/m-p/165059#M53131</guid>
      <dc:creator>davanderson</dc:creator>
      <dc:date>2017-07-06T20:02:18Z</dc:date>
    </item>
  </channel>
</rss>

