<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT rule to change internal IP to another on same subnet? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176401#M55170</link>
    <description>&lt;P&gt;Thank you.&amp;nbsp; Do you know if that would effect communications with clients that are currently connecting and using IP 192.168.1.19 directly?&lt;/P&gt;</description>
    <pubDate>Wed, 13 Sep 2017 17:19:55 GMT</pubDate>
    <dc:creator>OMatlock</dc:creator>
    <dc:date>2017-09-13T17:19:55Z</dc:date>
    <item>
      <title>NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176384#M55164</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created a internal zone&amp;nbsp;IP address I want to use as generic for FTP communications 192.168.1.9.&lt;/P&gt;&lt;P&gt;I want to NAT this IP to our current FTP server 192.168.1.19.&amp;nbsp; This way when our FTP server changes we just change our NAT rule rather than the rest of our partner companies firewalls, routes, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've created a DNAT rule and able to ping 192.168.1.9 and get a response from 192.168.1.19, but unable to connect via ftp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've done this before successfully between network zones (subnets) but not on the same zone (subnet) so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 16:29:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176384#M55164</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-09-13T16:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176390#M55165</link>
      <description>&lt;P&gt;Hey do I understand correctly that clients and FTP server are both internal in&amp;nbsp;&lt;SPAN&gt;192.168.1.x subnet?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you show your DNAT rule?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 16:37:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176390#M55165</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-13T16:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176392#M55166</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; Maybe I should create a source bi-directional rule.&amp;nbsp; But do not want to disturb regular traffic to 192.168.1.19.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FTP-IP1 = 192.168.1.9&lt;/P&gt;&lt;P&gt;Private = 192.168.1.19&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTP_NAT.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11261i00C59C6A5EF528C9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="FTP_NAT.jpg" alt="FTP_NAT.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 16:49:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176392#M55166</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-09-13T16:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176396#M55168</link>
      <description>&lt;P&gt;You have to add source nat also to the rule.&lt;/P&gt;&lt;P&gt;Traffic must source from firewall internal IP.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 16:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176396#M55168</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-13T16:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176401#M55170</link>
      <description>&lt;P&gt;Thank you.&amp;nbsp; Do you know if that would effect communications with clients that are currently connecting and using IP 192.168.1.19 directly?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 17:19:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176401#M55170</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-09-13T17:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176402#M55171</link>
      <description>&lt;P&gt;This does not affect users connecting directly to .19&lt;/P&gt;&lt;P&gt;Issue is that if client from 192.168.1.x network connects to&amp;nbsp;&lt;SPAN&gt;192.168.1.9 that is DNATed further to&amp;nbsp;192.168.1.19 then reply packet is sent directly to original source IP because&amp;nbsp;192.168.1.19 identifies that source is in it's own subnet and does not need to send this packet to gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Client who received reply packet from&amp;nbsp;192.168.1.19 will drop it because it does not know anything about&amp;nbsp;192.168.1.19 as client initiated connection to&amp;nbsp;192.168.1.9&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 17:49:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/176402#M55171</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-13T17:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/177788#M55401</link>
      <description>&lt;P&gt;I will come back to this one.&amp;nbsp; Unfortunately other projects, tasks, and priorities are totally interupting what I was doing here, but still need to confirm.&amp;nbsp; I will schedule some time soon to finish this thread.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 07:25:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/177788#M55401</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-09-20T07:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/179876#M55765</link>
      <description>&lt;P&gt;Thanks Raido,&lt;/P&gt;&lt;P&gt;I would like to resolve this thread this week.&lt;/P&gt;&lt;P&gt;I have my DNAT rule in place and I can ping 192.168.1.9 (VIP)&amp;nbsp;and get a response from 192.168.1.19 (FTP server), but ftp does not work when I try &lt;A href="ftp://192.168.1.9" target="_blank"&gt;ftp://192.168.1.9&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would I set up the correct SNAT rule for this to work?&amp;nbsp; I just tried this SNAT rule, but not working so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SNAT.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11730iE1F8C8969C0BA3CA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SNAT.jpg" alt="SNAT.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 16:36:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/179876#M55765</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-10-03T16:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/179904#M55781</link>
      <description>&lt;P&gt;Your original DNAT rule was fine.&lt;/P&gt;&lt;P&gt;All you were missing was Source NAT field.&lt;/P&gt;&lt;P&gt;Do not change other fields in your initial rule.&lt;/P&gt;&lt;P&gt;You need to have both Source NAT and Destination NAT configured in this single NAT policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assume that your firewall internal IP is 192.168.1.1&lt;/P&gt;&lt;P&gt;In this case Source NAT is from this&amp;nbsp;&lt;SPAN&gt;192.168.1.1 IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;From zone - Trust&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To zone - Trust&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Source address - Any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Destination address - 192.168.1.9&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Source translation - Dynamic-ip-port 192.168.1.1 (assuming this is your fw internal IP)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Destination translation - 192.168.1.19&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 21:50:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/179904#M55781</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-03T21:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/180816#M55912</link>
      <description>&lt;P&gt;Thanks Raido,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is working for me internally now.&amp;nbsp; Still trying to wrap my head around it.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, it does not work externally.&amp;nbsp; I have a security rule that opens everything to my public IP.&amp;nbsp; I have a NAT rule that translates public IP to 192.168.1.9 (and a source Dynamic IP and port to external interface IP).&amp;nbsp; Neither http or ftp work, just times out.&amp;nbsp; (I have a web server and ftp server here)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Curious if you comments about external connectivity?&lt;/P&gt;&lt;P&gt;Thank you for your guidance...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="securities.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11847i6B87B83BCF09E6B7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="securities.jpg" alt="securities.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Internet = 96.68.102.140 (one of my public IPs I use for internet access)&lt;/P&gt;&lt;P&gt;Copperfield = 192.168.1.1 (IP of internal LAN Interface)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NATs.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11848iFD301D9D3FD2805A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NATs.jpg" alt="NATs.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 12:51:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/180816#M55912</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-10-09T12:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/181504#M56056</link>
      <description>&lt;P&gt;For it to work from outside you need:&lt;/P&gt;&lt;P&gt;From zone - Untrust&lt;/P&gt;&lt;P&gt;To zone - Untrust&lt;/P&gt;&lt;P&gt;Destination Address - 96.68.102.139&lt;/P&gt;&lt;P&gt;Service - create new tcp-21 with protocol tcp and port 21&lt;/P&gt;&lt;P&gt;Destination translation - 192.168.32.19&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NB! Place this new wan rule above WebServer1 rule because otherwise WebServer1 will NAT all ports to 192.168.1.9&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 14:37:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/181504#M56056</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-12T14:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rule to change internal IP to another on same subnet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/182049#M56136</link>
      <description>&lt;P&gt;Wow, thanks Raido!&lt;/P&gt;&lt;P&gt;I starting to get it.&amp;nbsp; I need to spend more time in wireshark to understand it better.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for your responses.&amp;nbsp; Creating this internal "VIP" will help in communicating a long term IP to our IPSec VPN connections that will allow us to change servers and IPs without the need to have our partners update their rules, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Final NAT rules.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT_VIP.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11962i9184671ECB35EB19/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT_VIP.jpg" alt="NAT_VIP.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 15:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-to-change-internal-ip-to-another-on-same-subnet/m-p/182049#M56136</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-10-16T15:20:34Z</dc:date>
    </item>
  </channel>
</rss>

