<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Feature request thoughts - around nat selection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/feature-request-thoughts-around-nat-selection/m-p/226791#M65292</link>
    <description>&lt;P&gt;Thought I would give it a try&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Default Outbound NAT DST - 0 Dynamic IP/Port 325 257723 36472 4&lt;BR /&gt;Default Outbound NAT DST - 1 Dynamic IP/Port 325 257723 36472 4&lt;BR /&gt;Default Outbound Non Prod - 0 Dynamic IP/Port 0 258048 36472 4&lt;BR /&gt;Default Outbound Non Prod - 1 Dynamic IP/Port 0 258048 36472 4&lt;BR /&gt;Default Outbound - 0 Dynamic IP/Port 325 257723 36472 4&lt;BR /&gt;Default Outbound - 1 Dynamic IP/Port 325 257723 36472 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;seems like it groups all the same ip address together you can see the top 2 and the bottom 2 match the same port count use&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thats good&lt;/P&gt;</description>
    <pubDate>Sat, 11 Aug 2018 05:27:40 GMT</pubDate>
    <dc:creator>Alex_Samad</dc:creator>
    <dc:date>2018-08-11T05:27:40Z</dc:date>
    <item>
      <title>Feature request thoughts - around nat selection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/feature-request-thoughts-around-nat-selection/m-p/226790#M65291</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 NAT pools, actually 4, cause for HA each pool is doubled - does that make sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 pool is on a.b.c.13 and the second is on a.b.c.113.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All good. what I would like to do is say&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;going out internet interface from src group "out via non prod" nat to a.b.c.113&lt;/P&gt;&lt;P&gt;going out internet interface from src group "inside ip address" nat to a.b.c.13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but&amp;nbsp; there are some addresses that need to only go via the prod ip (a.b.c.13).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what i found is I can't in my destination selection use a negative address range (I think this would be a good idea - thought I would float here before talking to the SE).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my other alternative is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;going out internet interface from src group "inside ip address" and destination "is nat only dst"nat to a.b.c.13&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;going out internet interface from src group "out via non prod" nat to a.b.c.113&lt;/P&gt;&lt;P&gt;going out internet interface from src group "inside ip address" nat to a.b.c.13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I am not sure how it would having 2 active pools on the same address is that allowed, i am guessing it is cause i actually have&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;bound to node 0 on active active&lt;/P&gt;&lt;P&gt;going out internet interface from src group "out via non prod" nat to a.b.c.113&lt;/P&gt;&lt;P&gt;going out internet interface from src group "inside ip address" nat to a.b.c.13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;bound to node 1 on active active&lt;/P&gt;&lt;P&gt;going out internet interface from src group "out via non prod" nat to a.b.c.113&lt;/P&gt;&lt;P&gt;going out internet interface from src group "inside ip address" nat to a.b.c.13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so if node 1 or node 0 fails there would be 2 sete of active pools on the same node ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 05:14:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/feature-request-thoughts-around-nat-selection/m-p/226790#M65291</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-08-11T05:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Feature request thoughts - around nat selection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/feature-request-thoughts-around-nat-selection/m-p/226791#M65292</link>
      <description>&lt;P&gt;Thought I would give it a try&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Default Outbound NAT DST - 0 Dynamic IP/Port 325 257723 36472 4&lt;BR /&gt;Default Outbound NAT DST - 1 Dynamic IP/Port 325 257723 36472 4&lt;BR /&gt;Default Outbound Non Prod - 0 Dynamic IP/Port 0 258048 36472 4&lt;BR /&gt;Default Outbound Non Prod - 1 Dynamic IP/Port 0 258048 36472 4&lt;BR /&gt;Default Outbound - 0 Dynamic IP/Port 325 257723 36472 4&lt;BR /&gt;Default Outbound - 1 Dynamic IP/Port 325 257723 36472 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;seems like it groups all the same ip address together you can see the top 2 and the bottom 2 match the same port count use&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thats good&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 05:27:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/feature-request-thoughts-around-nat-selection/m-p/226791#M65292</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-08-11T05:27:40Z</dc:date>
    </item>
  </channel>
</rss>

