<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall not advertising the public IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172755#M54469</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;We want to allow traffic from outside&amp;nbsp;to come inside our server however cannot see any traffic unless loopback is used. This server is behind DMZ. We can solve the public IP address of the server when we go to &lt;A href="http://www.whatismyip.com" target="_blank"&gt;www.whatismyip.com&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Traceroute&amp;nbsp;stops at 13&lt;/SPAN&gt;th&lt;SPAN&gt;&amp;nbsp;hop before we added loopback&amp;nbsp;for the public IP.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We are using&amp;nbsp;Source NAT&amp;nbsp;like below:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;In the Original Packet tab: Source Zone=DMZ, Destination Zone=WAN, Destination Interface=any, Service=any, Source Address=Local IP address of DMZ, Destination Address=any.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;In the Translated Packet tab: Under Source Address Translation, Translation Type=Static IP, Translated Address=Public IP address of server, check Bi-directional.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We are using security policy as below:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Select Source Zone=Outside/WAN, Source Address=any, Destination Zone=DMZ, Destination Address=Public Address of the server, Application=ssl, Service=application-default, URL category=any, Action=allow.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Is there a solution wherein the NATing works without adding loopback or is it that loopbacks are mandatory for NATing?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 23 Aug 2017 06:47:46 GMT</pubDate>
    <dc:creator>Farzana</dc:creator>
    <dc:date>2017-08-23T06:47:46Z</dc:date>
    <item>
      <title>Firewall not advertising the public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172755#M54469</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;We want to allow traffic from outside&amp;nbsp;to come inside our server however cannot see any traffic unless loopback is used. This server is behind DMZ. We can solve the public IP address of the server when we go to &lt;A href="http://www.whatismyip.com" target="_blank"&gt;www.whatismyip.com&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Traceroute&amp;nbsp;stops at 13&lt;/SPAN&gt;th&lt;SPAN&gt;&amp;nbsp;hop before we added loopback&amp;nbsp;for the public IP.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We are using&amp;nbsp;Source NAT&amp;nbsp;like below:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;In the Original Packet tab: Source Zone=DMZ, Destination Zone=WAN, Destination Interface=any, Service=any, Source Address=Local IP address of DMZ, Destination Address=any.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;In the Translated Packet tab: Under Source Address Translation, Translation Type=Static IP, Translated Address=Public IP address of server, check Bi-directional.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We are using security policy as below:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Select Source Zone=Outside/WAN, Source Address=any, Destination Zone=DMZ, Destination Address=Public Address of the server, Application=ssl, Service=application-default, URL category=any, Action=allow.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Is there a solution wherein the NATing works without adding loopback or is it that loopbacks are mandatory for NATing?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 23 Aug 2017 06:47:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172755#M54469</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-08-23T06:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall not advertising the public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172781#M54473</link>
      <description>&lt;P&gt;Is the public IP address you used in the translation part of the subnet that's configured on the WAN interface ?&lt;/P&gt;
&lt;P&gt;If you add the subnet to the external interface, this will simplify proxy-arp broadcasts.&amp;nbsp; Else, a loopback interface in the wan zone will do the trick&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 09:03:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172781#M54473</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-08-23T09:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall not advertising the public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172787#M54477</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, the public IP address is not part of the WAN interface subnet. We have already added the loopback in the WAN zone and it works. Ques is:&amp;nbsp;&lt;SPAN&gt;is there a solution wherein the NATing works without adding loopback or is it that loopbacks are mandatory for NATing?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10886iCDED9E8E3F836BFF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10887i13F85521D8A6664A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 09:15:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172787#M54477</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-08-23T09:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall not advertising the public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172790#M54480</link>
      <description>&lt;P&gt;the firewall needs to determine to which interface the IP address belongs for it to be able to send out proxy arp (else it could flood out all interfaces). therefore you should add the subnet to the external interface (or use individual loopbacks)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you don't want to add the subnet or use loopbacks, you can create static ARP entries on the upstream router that point to your firewall interface for the desired IPs also&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 09:19:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172790#M54480</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-08-23T09:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall not advertising the public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172791#M54481</link>
      <description>&lt;P&gt;I just feel expertise in your responses&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 09:24:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-not-advertising-the-public-ip/m-p/172791#M54481</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-23T09:24:31Z</dc:date>
    </item>
  </channel>
</rss>

