<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't create Nat rule using more than one source address in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240737#M68955</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;thank you for the reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My goal here is to create Nat rule for two internal servers that go out using the same external IP,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only for outbound direction no bi-directional.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to use their IP address /32 and also for the static IP /32 without success.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nat rule fail.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17614iF8BF358EFE7AB569/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="nat rule fail.jpg" alt="nat rule fail.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Nov 2018 15:36:26 GMT</pubDate>
    <dc:creator>SShnap</dc:creator>
    <dc:date>2018-11-21T15:36:26Z</dc:date>
    <item>
      <title>Can't create Nat rule using more than one source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240655#M68935</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to create Nat rule for source translate when the source is address group and it will not be bi-directional.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The address group include 2 address from objects.&lt;/P&gt;&lt;P&gt;The source translate is Static-IP tried to put object and specifric IP address with subnet (/32)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I keep receiving the following error, also tried to use two-source address instead of address group with success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm on PANOS 8.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Nat rule error.jpg" style="width: 670px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17609i5E84F865080C65E9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Nat rule error.jpg" alt="Nat rule error.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 23:30:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240655#M68935</guid>
      <dc:creator>SShnap</dc:creator>
      <dc:date>2018-11-20T23:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can't create Nat rule using more than one source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240666#M68936</link>
      <description>&lt;P&gt;If you have&amp;nbsp; more than 1 IPs on one side then&amp;nbsp; you have to have same amount at other side to use static nat.&lt;/P&gt;&lt;P&gt;Static nat leaves port number the same so if source sends traffic out from port 1234 then after static nat source port is still 1234.&lt;/P&gt;&lt;P&gt;In case of&amp;nbsp;Dynamic IP And Port option source port is changed so multiple source IPs can be behind one IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case you have to use&amp;nbsp;Dynamic IP And Port option.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 03:12:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240666#M68936</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-21T03:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can't create Nat rule using more than one source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240702#M68941</link>
      <description>&lt;P&gt;This will work (bi-directional static nat for a bunch of ip&amp;nbsp;addresses) only if you set your original source addresses to a subnet (not a group object) and the subnet mask needs to exactly match the translation subnet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bidir static subnet.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17610i603E37D6E89BE460/image-size/large?v=v2&amp;amp;px=999" role="button" title="bidir static subnet.png" alt="bidir static subnet.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 09:09:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240702#M68941</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-11-21T09:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can't create Nat rule using more than one source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240737#M68955</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;thank you for the reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My goal here is to create Nat rule for two internal servers that go out using the same external IP,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only for outbound direction no bi-directional.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to use their IP address /32 and also for the static IP /32 without success.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nat rule fail.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17614iF8BF358EFE7AB569/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="nat rule fail.jpg" alt="nat rule fail.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 15:36:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240737#M68955</guid>
      <dc:creator>SShnap</dc:creator>
      <dc:date>2018-11-21T15:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can't create Nat rule using more than one source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240741#M68957</link>
      <description>&lt;P&gt;In this case you can't use static-ip.&lt;/P&gt;&lt;P&gt;Choose "&lt;SPAN&gt;Dynamic IP And Port" from droppdown.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 15:57:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240741#M68957</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-21T15:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can't create Nat rule using more than one source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240744#M68959</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;, for the dynamic IP and port it allows my to apply that Nat rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How it will behave if those servers are exhcnage servers in DAG design and the outbound traffic is 25 SMTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the smtp traffic will work on the other end? sending emails out?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 16:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240744#M68959</guid>
      <dc:creator>SShnap</dc:creator>
      <dc:date>2018-11-21T16:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can't create Nat rule using more than one source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240758#M68962</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/40971"&gt;@SShnap&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Email systems really don't care about the source-port the traffic is coming from; the traffic just need to hit and open port on the other end.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 17:29:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-nat-rule-using-more-than-one-source-address/m-p/240758#M68962</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-21T17:29:16Z</dc:date>
    </item>
  </channel>
</rss>

