<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create an internal type NAT? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/169093#M53767</link>
    <description>&lt;P&gt;Thanks!&amp;nbsp; I think you mean a DNAT that could say destination of ip 10.1.5.252 translate to 10.1.2.15?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.1.5.252 is the interface IP on our 3020 that represents their network (gateway).&amp;nbsp; Maybe that could work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've not done this scenario, will try it on my home PA 200 and report back.&lt;/P&gt;</description>
    <pubDate>Mon, 31 Jul 2017 16:34:58 GMT</pubDate>
    <dc:creator>OMatlock</dc:creator>
    <dc:date>2017-07-31T16:34:58Z</dc:date>
    <item>
      <title>How to create an internal type NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/169071#M53764</link>
      <description>&lt;P&gt;Hello folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if my question is worded just right, but here goes. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a partner company that has a Juniper NAT type of device plugged into our PA 3020 that does a NAT to a server in there environment, which we communicate with fine using the 10.1.5.x network.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am being asked to do something similar on our side.&amp;nbsp; Today they are able to communicate with our server using its 10.1.2.15 address (production subnet).&amp;nbsp; My manager is asking if I could create an IP that is not on our production subnet but then will NAT to the 10.1.2.15 instead.&amp;nbsp; This is so that if/when an IP needs to change, we would just change the firewall rule and also to not expose details about our production subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would anyone have a suggestion for how to do this?&amp;nbsp; Loopback and DNAT in some way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current config on left, proposed on the right:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PANAT.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10562i81D1FF44F60F9ECF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PANAT.jpg" alt="PANAT.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 15:48:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/169071#M53764</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-07-31T15:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to create an internal type NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/169080#M53765</link>
      <description>&lt;P&gt;Can you simply have DNAT on the Palo&amp;nbsp;&lt;SPAN&gt;10.1.5.252 ip address?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 16:07:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/169080#M53765</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-31T16:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to create an internal type NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/169093#M53767</link>
      <description>&lt;P&gt;Thanks!&amp;nbsp; I think you mean a DNAT that could say destination of ip 10.1.5.252 translate to 10.1.2.15?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.1.5.252 is the interface IP on our 3020 that represents their network (gateway).&amp;nbsp; Maybe that could work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've not done this scenario, will try it on my home PA 200 and report back.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 16:34:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/169093#M53767</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-07-31T16:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to create an internal type NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/169134#M53772</link>
      <description>&lt;P&gt;Interesting scenario with&amp;nbsp;DG, but yeah it should work. Why not. Just give a go&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 20:01:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/169134#M53772</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-31T20:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to create an internal type NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/170506#M54052</link>
      <description>&lt;P&gt;Thank you for the feedback!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe I have worked something out here.&amp;nbsp; Considering that I needed two IP addresses, I can not use the gateway IP.&amp;nbsp; However, your suggestion gives guidance that I can use the 10.1.5.x network as a shared network (subnet) between the two of us.&amp;nbsp; I was orginally considering creating a new subnet somehow.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will will be doing a NAT from this network to separate (or "mask")&amp;nbsp;our respective inside production networks from each other.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I get back from vacation (worked it out day before I left), I will add my rules and diagram for reference.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 12:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/170506#M54052</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-08-08T12:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to create an internal type NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/170514#M54054</link>
      <description>&lt;P&gt;You can use any spare ip&amp;nbsp;within the&amp;nbsp;&lt;SPAN&gt;10.1.5.x subnet in DNAT config. Firewall will reply for ARP request by default for that&amp;nbsp;ip&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 12:44:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/170514#M54054</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-08T12:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to create an internal type NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/174601#M54848</link>
      <description>&lt;P&gt;Yea I believe I understand this now.&amp;nbsp; I can use any 10.1.5.x IP.&amp;nbsp; We are using 10.1.5.x as a common network between us and use NAT rules to "hide" the details of our internal networks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got this working at my job as well.&amp;nbsp; I am posting my test sample configuration here for reference and close this thread.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNAT rule.&amp;nbsp; Of course I have a security rule in place that allows permissions between the zones.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNAT.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11013iFCE3F3AB8245DF31/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DNAT.jpg" alt="DNAT.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Diagram&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="visioDNAT.jpg" style="width: 454px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11014iF5685A723326F4C2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="visioDNAT.jpg" alt="visioDNAT.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2017 13:13:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-an-internal-type-nat/m-p/174601#M54848</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-09-04T13:13:23Z</dc:date>
    </item>
  </channel>
</rss>

