<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpenVPN to a server behind PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/186757#M56927</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12405i6F06A4124B54F937/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT.PNG" alt="NAT" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;NAT&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rule" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12406iE953CCAD5E5C61B7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rule.png" alt="Rule" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Rule&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Nov 2017 20:20:50 GMT</pubDate>
    <dc:creator>solarstone</dc:creator>
    <dc:date>2017-11-13T20:20:50Z</dc:date>
    <item>
      <title>OpenVPN to a server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/186707#M56920</link>
      <description>&lt;P&gt;I have a dest NAT setup with port translation thus:&lt;/P&gt;&lt;P&gt;untrust untrust public IP tcp 443 &amp;gt; private IP tcp 1194&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy set as&lt;/P&gt;&lt;P&gt;untrust trust any src to public IP for 443.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The NAT works fine, but I see aged-out on the traffic monitor, and no traffic at all on wireshark on my PA &amp;gt; Server LAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 16:00:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/186707#M56920</guid>
      <dc:creator>solarstone</dc:creator>
      <dc:date>2017-11-13T16:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN to a server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/186753#M56926</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73783"&gt;@solarstone&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Could you take a screenshot of the actual rule you have configured.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 19:59:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/186753#M56926</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-13T19:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN to a server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/186757#M56927</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12405i6F06A4124B54F937/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT.PNG" alt="NAT" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;NAT&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rule" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12406iE953CCAD5E5C61B7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rule.png" alt="Rule" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Rule&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 20:20:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/186757#M56927</guid>
      <dc:creator>solarstone</dc:creator>
      <dc:date>2017-11-13T20:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN to a server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/187822#M57092</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73783"&gt;@solarstone&lt;/a&gt;:&lt;/P&gt;&lt;P&gt;You hide important port of Your rules...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please take a look at my example:&lt;/P&gt;&lt;P&gt;Security rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-11-19_154137.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12514iF2B121CC71556D72/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2017-11-19_154137.png" alt="2017-11-19_154137.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;NAT rule&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-11-19_152457.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12515i4EB8669FC8BA9653/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2017-11-19_152457.png" alt="2017-11-19_152457.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In You case in security rule insted of my ms-rdp and t.120 please put any but in service please create your own service with port 443.&lt;/P&gt;&lt;P&gt;In NAT as a "public IP" please put your public address of VPN serwer, as RDP 3502 please use Your serice 443. As "address k133" please put local IP (from DMZ) of Your VPN, insted of 3389 please put 1194. That's it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I advice You to read carefully this article &lt;A href="https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Understanding-PAN-OS-NAT/ta-p/60965" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Understanding-PAN-OS-NAT/ta-p/60965&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Sun, 19 Nov 2017 18:39:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/187822#M57092</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2017-11-19T18:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN to a server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/187913#M57105</link>
      <description>&lt;P&gt;Thanks for the response, how you describe is how I have it setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have replicated (with diff address) the&amp;nbsp;NAT, and policy rules, for an internal IIS server, and that connects fine. Hence my issue appears to be with the the ongoing LAN connection from inside the PA, to the OpenVPN server. No traffic reaches it. Whether this is a PA issue (I sense not, now) or an issue with the L2 path behind the PA on the LAN, I don't yet know.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 10:06:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/187913#M57105</guid>
      <dc:creator>solarstone</dc:creator>
      <dc:date>2017-11-20T10:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN to a server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/187922#M57107</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm glad to hear that is started working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If You have problem with conenction from LAN to DMZ You need to create another rules (in PaloAlto knows as U-turn rules) please read tech doc that I mention or find using search button how to create it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regatrds&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 10:49:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/187922#M57107</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2017-11-20T10:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN to a server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/187924#M57108</link>
      <description>&lt;P&gt;It isn't working. What I'm saying is that if I use the same NAT/Policy rules (with diff addresses) and try to connect to the IIS server using the destination NAT with port translastion, I see traffic from the PA internal LAN&amp;nbsp;interface to the web server on that network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I use the same theory to connect to the OpenVPN server, there is nothing at all on the LAN between PA and OpenVPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;e.g. NAT 1.2.3.4 port 443&amp;nbsp; translates to 10.1.1.2 port 1194.&amp;nbsp; From an external source, if I try to connect to 1.2.3.4:443, then the PA performs the NAT translation, the traffic is allowed, but that's where it ends. There is no traffic between PA interface 10.1.1.1 and openVPN on 10.1.1.2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hairpinning is if I'm trying to connect from inside to out, on the external address, and back in. I don't need to do this as far as I'm aware.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 11:06:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-to-a-server-behind-pa/m-p/187924#M57108</guid>
      <dc:creator>solarstone</dc:creator>
      <dc:date>2017-11-20T11:06:23Z</dc:date>
    </item>
  </channel>
</rss>

