<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue NAT via VPN tunnel - VPN zone to Trusted zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-nat-via-vpn-tunnel-vpn-zone-to-trusted-zone/m-p/184018#M56474</link>
    <description>&lt;P&gt;I don't have an Untrusted zone as an option. But yes the 172.25.43.1/32 is just an object to match Proxy-ID setup in a VPN tunnel. It is not a part of an internal network. I do have active security polices allowing these Inside, DMZ and Subnets between them and the VPN zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the destination NAT that doesn't work.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT-Trans-Not-Working.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12134i5753B82E4FFCDA20/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT-Trans-Not-Working.PNG" alt="NAT-Trans-Not-Working.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;These are source NAT entries that work only when traffic is initiated from Trusted or DMZ resouces. When traffic is initiated from the VPN resource it doesn't work. Even when Bi-Directional is enabled. On most firewalls this source NAT configuration set to Bi-Directional is all that is required.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT-Trans-Working.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12135i3C1B87E26E45D498/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT-Trans-Working.PNG" alt="NAT-Trans-Working.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2017 22:02:21 GMT</pubDate>
    <dc:creator>bshuman</dc:creator>
    <dc:date>2017-10-26T22:02:21Z</dc:date>
    <item>
      <title>Issue NAT via VPN tunnel - VPN zone to Trusted zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-nat-via-vpn-tunnel-vpn-zone-to-trusted-zone/m-p/181359#M56035</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;I'm having a very similar issue with trying to configure a NAT translation from VPN to Trusted zone. In my case I'm building a VPN tunnel for monitoring using /32 ProxyIDs. My configuration VPN ProxyID is like the example below:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;Remote:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Local:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;3.3.3.3/32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; 172.25.40.3/32&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;My NAT is configured as follows.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;Source Zone:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dest Zone:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dest Address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination Trans:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;VPN &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trusted&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.3.3.3/32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.25.40.3/32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.100.10.10/32&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;I can't get the translation to happen when send pings from the VPN and that's what I need working. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;If I switch from a Dest translation to Source translation it works when I ping from Trust to VPN. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;Source Zone:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dest Zone:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dest Address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Trans:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;Trusted&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.100.10.10/32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.3.3.3/32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.25.40.3/32&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;What am I missing? Do I need to add a static route for the V-Router? To get to 172.25.40.0/32 use tunnl.x?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;Please advise. Thanks. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead"&gt;&lt;SPAN class=""&gt;Ben&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 17:57:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-nat-via-vpn-tunnel-vpn-zone-to-trusted-zone/m-p/181359#M56035</guid>
      <dc:creator>bshuman</dc:creator>
      <dc:date>2017-10-11T17:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Issue NAT via VPN tunnel - VPN zone to Trusted zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-nat-via-vpn-tunnel-vpn-zone-to-trusted-zone/m-p/181384#M56037</link>
      <description>&lt;P&gt;I assume that you are not using&amp;nbsp;&lt;SPAN&gt;172.25.40.3/32&amp;nbsp; in your network internally.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It means that based on routing table traffic to this IP is sent towards Untrust zone.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So for NAT to match it should be VPN &amp;gt; Untrust (not Trust).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And you also might need second NAT rule if traffic is initiated from inside.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In this case it is Trust &amp;gt; VPN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 19:04:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-nat-via-vpn-tunnel-vpn-zone-to-trusted-zone/m-p/181384#M56037</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-11T19:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue NAT via VPN tunnel - VPN zone to Trusted zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-nat-via-vpn-tunnel-vpn-zone-to-trusted-zone/m-p/183491#M56381</link>
      <description>&lt;P&gt;I'll try that. Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 17:35:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-nat-via-vpn-tunnel-vpn-zone-to-trusted-zone/m-p/183491#M56381</guid>
      <dc:creator>bshuman</dc:creator>
      <dc:date>2017-10-24T17:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue NAT via VPN tunnel - VPN zone to Trusted zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-nat-via-vpn-tunnel-vpn-zone-to-trusted-zone/m-p/184018#M56474</link>
      <description>&lt;P&gt;I don't have an Untrusted zone as an option. But yes the 172.25.43.1/32 is just an object to match Proxy-ID setup in a VPN tunnel. It is not a part of an internal network. I do have active security polices allowing these Inside, DMZ and Subnets between them and the VPN zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the destination NAT that doesn't work.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT-Trans-Not-Working.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12134i5753B82E4FFCDA20/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT-Trans-Not-Working.PNG" alt="NAT-Trans-Not-Working.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;These are source NAT entries that work only when traffic is initiated from Trusted or DMZ resouces. When traffic is initiated from the VPN resource it doesn't work. Even when Bi-Directional is enabled. On most firewalls this source NAT configuration set to Bi-Directional is all that is required.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT-Trans-Working.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12135i3C1B87E26E45D498/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT-Trans-Working.PNG" alt="NAT-Trans-Working.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 22:02:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-nat-via-vpn-tunnel-vpn-zone-to-trusted-zone/m-p/184018#M56474</guid>
      <dc:creator>bshuman</dc:creator>
      <dc:date>2017-10-26T22:02:21Z</dc:date>
    </item>
  </channel>
</rss>

