<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Source NAT subnet from wrong interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188510#M57205</link>
    <description>&lt;P&gt;If you have no need to control traffic between the zone 1 and zone 2, I see no reason to create the two interfaces and zones on the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what you describe I assume that the single default route of your switch along with local routing is having all the traffic from both subnets arrrive on the PA via your "zone 1" interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can simply treat both subnets as the same zone and have a route on the PA that pushes the second subnet out the existing "zone 1" interface and delete the zone 2 interface entirely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any special treatment of the two subnets could be handled by security policies based simply on the subnet in the same zone just as easily for the external internet access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Nov 2017 12:43:52 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2017-11-23T12:43:52Z</dc:date>
    <item>
      <title>Source NAT subnet from wrong interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188473#M57200</link>
      <description>&lt;P&gt;Hi, So im having difficult with a source nat to Internet.. My goal is to route traffic between two vlans in my cisco 2960x switch and let palo handle the rest.. The problem is that the source net arrives to the palo on the wrong interface (well its expected..)&lt;/P&gt;&lt;P&gt;i have zone already configuerd in the palo fw with zones, interface. Ive created a access rule from zone1, with source net 10.20.31.0 and i see in the log that the traffic allows from zone1 with source net 10.20.31.0.. But the NAT rule i cant get to work.. need help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;palo&lt;/P&gt;&lt;P&gt;zone1: 10.20.30.0&lt;/P&gt;&lt;P&gt;zone2: 10.20.31.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2960x&lt;/P&gt;&lt;P&gt;vlan1: 10.20.30.0&lt;/P&gt;&lt;P&gt;vlan2:10.20.31.0&lt;/P&gt;&lt;P&gt;vlan1-2 routes in cisco 2960x&lt;/P&gt;&lt;P&gt;default route to 10.20.30.2 (palo)&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 07:47:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188473#M57200</guid>
      <dc:creator>Pederjohansson</dc:creator>
      <dc:date>2017-11-23T07:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Source NAT subnet from wrong interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188495#M57202</link>
      <description>&lt;P&gt;Can you provide some more details,. like for example what you mean with 'wrong interface' as this is not clear from your explanation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you create 2 subinterfaces, each with their own zone/vlan tag?&lt;/P&gt;
&lt;P&gt;If you want to route between the 2 vlans adn perform NAT it's probably better to have the firewall perform routing while also taking care of NAT&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 09:23:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188495#M57202</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-23T09:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Source NAT subnet from wrong interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188510#M57205</link>
      <description>&lt;P&gt;If you have no need to control traffic between the zone 1 and zone 2, I see no reason to create the two interfaces and zones on the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what you describe I assume that the single default route of your switch along with local routing is having all the traffic from both subnets arrrive on the PA via your "zone 1" interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can simply treat both subnets as the same zone and have a route on the PA that pushes the second subnet out the existing "zone 1" interface and delete the zone 2 interface entirely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any special treatment of the two subnets could be handled by security policies based simply on the subnet in the same zone just as easily for the external internet access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 12:43:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188510#M57205</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-11-23T12:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Source NAT subnet from wrong interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188511#M57206</link>
      <description>&lt;P&gt;palo config (updated)&lt;/P&gt;&lt;P&gt;zone1: 10.20.30.0 subinterface attached with own zone, vlan tag&lt;/P&gt;&lt;P&gt;zone2: 10.20.31.0 subinterface attached with own zone, vlan tag&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what i mean with wrong interface is that 10.20.31.0 client traffic hits the "zone1" zone (zone1, source address 10.20.31.0) in the fw because the default route in the switch is 10.20.30.4.. i&amp;nbsp;want the switch to handle routing to have high Throughput. So im struggeling with the NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How should a nat be created for this?&lt;/P&gt;&lt;P&gt;Is&amp;nbsp;it possible to do this, with diffrent zones ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or do i need to put both subnet in one zone? (this works, but then i need to change all access rules to check source network 10.20.31 or 10.20.30 to control the traffic.)&lt;/P&gt;&lt;P&gt;Is this good solution? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 12:51:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188511#M57206</guid>
      <dc:creator>Pederjohansson</dc:creator>
      <dc:date>2017-11-23T12:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: Source NAT subnet from wrong interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188513#M57207</link>
      <description>&lt;P&gt;thanks for the input puklukas, i belive it is better to treat both subnets as the same zone after some testing today. if i trust the traffic in the switch i can trust it in PA and set security rules on the source address. I will test some more.. But for the NAT is it even possible for the PA to handle this? (If a seperate the two subnets to diffrent zones)&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 13:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188513#M57207</guid>
      <dc:creator>Pederjohansson</dc:creator>
      <dc:date>2017-11-23T13:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Source NAT subnet from wrong interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188694#M57229</link>
      <description>&lt;P&gt;You pretty much have to have these two interfaces in the same zone.&amp;nbsp; As you note, there is only one default route on the switch so all the traffic out will use that interface to the PA regardless of which subnet the computers are in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can then create two nat rules if you want the two subnets to nat to different addresses and that can easily be in the same zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess I am not understanding which configuration you are having problems making specific that cannot be done with the two subnets and interfaces in the same zone.&amp;nbsp; Can you post an example?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 16:12:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-nat-subnet-from-wrong-interface/m-p/188694#M57229</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-11-25T16:12:28Z</dc:date>
    </item>
  </channel>
</rss>

