<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating a Dynamic NAT and exclude addresses from pool in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8132#M6008</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have you tried to specify ranges that start @ .1 and end on .254 instead of using CIDR notation?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Nov 2011 08:25:41 GMT</pubDate>
    <dc:creator>bpappas</dc:creator>
    <dc:date>2011-11-09T08:25:41Z</dc:date>
    <item>
      <title>Creating a Dynamic NAT and exclude addresses from pool</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8129#M6005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are known issues online with some external sources not accepting addresses with the last octet ending in .0 or .255.&amp;nbsp; Are there any known ways to exclude these addresses from a Dynamic External IP Pool?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 14:14:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8129#M6005</guid>
      <dc:creator>bmorrison</dc:creator>
      <dc:date>2011-09-26T14:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a Dynamic NAT and exclude addresses from pool</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8130#M6006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The document at this link explains how to create a NAT policy which excludes addresses from a pool:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1258"&gt;https://live.paloaltonetworks.com/docs/DOC-1258&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 16:01:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8130#M6006</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2011-10-05T16:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a Dynamic NAT and exclude addresses from pool</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8131#M6007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This looks as if it would create a "No NAT" rule for the internal addressing.&amp;nbsp; I would need this to exclude addresses in the "External" addressing (Outside World).&amp;nbsp; I cannot create a rule simply being a range from .1-.254 because I am creating the rule to encompass the entire /21 external subnet, and the PA will not allow multiple external ranges in the translation of a single rule, so i would not be able to break these down per /24 external subnet and create the ranges excluding the .0 and .255 addresses.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 16:12:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8131#M6007</guid>
      <dc:creator>bmorrison</dc:creator>
      <dc:date>2011-10-05T16:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a Dynamic NAT and exclude addresses from pool</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8132#M6008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have you tried to specify ranges that start @ .1 and end on .254 instead of using CIDR notation?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Nov 2011 08:25:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8132#M6008</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-11-09T08:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a Dynamic NAT and exclude addresses from pool</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8133#M6009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This would not work, because the Palo-Alto does not support multiple external ranges within one Dynamic Policy.&amp;nbsp; Therefore you would only be able to create a single /24 network per policy, and that is not feasible in a system with over 10,000 internal users.&amp;nbsp; Currently, the PA does not support multiple external ranges per policy, or NAT/PAT overload.&amp;nbsp; This could easily be accomplished with a radio button to exempt network and broadcast addresses from the pool. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 21:03:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-a-dynamic-nat-and-exclude-addresses-from-pool/m-p/8133#M6009</guid>
      <dc:creator>bmorrison</dc:creator>
      <dc:date>2011-11-11T21:03:06Z</dc:date>
    </item>
  </channel>
</rss>

