<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure carrier data feed without dedicated router? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/configure-carrier-data-feed-without-dedicated-router/m-p/242117#M69304</link>
    <description>&lt;P&gt;Thats's a good question..&lt;BR /&gt;I would assume the routes are in their forwarding table since I can use SNAT rules to direct traffic over each of the 6 IP addresses&amp;nbsp;which I visually confirmed&amp;nbsp;with showmyip.net.&amp;nbsp; The response page wouldn't show if the route was missing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inbound (DNAT) is being tested&amp;nbsp;using the default IIS page with the system used in the outbound test.&amp;nbsp; Requests to the default page time out.&amp;nbsp; The security and NAT rules never increment. &amp;nbsp;Both rules&amp;nbsp;at the tops of their respective lists.&amp;nbsp; The page displays when requested from systems on the local LAN.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Dec 2018 21:29:06 GMT</pubDate>
    <dc:creator>BDS_Vince</dc:creator>
    <dc:date>2018-12-04T21:29:06Z</dc:date>
    <item>
      <title>Configure carrier data feed without dedicated router?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-carrier-data-feed-without-dedicated-router/m-p/242084#M69300</link>
      <description>&lt;P&gt;We are opening a new branch office and recieved notice that the carrier will not be providing a router and that it was our responsibility to perform the WAN to LAN routing.&lt;BR /&gt;&lt;BR /&gt;The carrier provided a layer 3 WAN block and a Customer Useable block containing 6 IP addresses.&lt;BR /&gt;&lt;BR /&gt;If I configure ethernet 1/1 with the WAN block IP address I can send/receive traffic using that IP address, I can send traffic (snat) out the interface using one of the Customer IP addresses.&amp;nbsp; The problem is that I can't receive (dnat) data from any of the customer IP addresses.&amp;nbsp; The NAT and Security policies are not used (counters are not incrementing).&lt;BR /&gt;&lt;BR /&gt;I believe the problem is that I need to add a route from the WAN ip address for the 6 customer IP addresses.&lt;BR /&gt;Can I use a static route or is this a case&amp;nbsp;for 2 virtual routers?&amp;nbsp; Routing is not my strong suit so any help will be greatly appreciated!&lt;BR /&gt;&lt;BR /&gt;TIA!&lt;BR /&gt;&lt;BR /&gt;Here is&amp;nbsp;the the cutsheet data (randomized)&lt;BR /&gt;WAN&lt;/P&gt;&lt;P&gt;Link IP: 40.202.237.172/30&lt;/P&gt;&lt;P&gt;GW&lt;SPAN&gt;: 40.202.237.173&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Layer 3 IP:&lt;SPAN&gt;: 40.202.237.174&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mask: 255.255.255.252&lt;BR /&gt;&lt;BR /&gt;Customer useable address block&lt;BR /&gt;Block: 50.206.224.144/29&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Range:&amp;nbsp;50.206.224.145-50.206.224.150&lt;BR /&gt;Mask: 255.255.255.248&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 19:25:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-carrier-data-feed-without-dedicated-router/m-p/242084#M69300</guid>
      <dc:creator>BDS_Vince</dc:creator>
      <dc:date>2018-12-04T19:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Configure carrier data feed without dedicated router?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-carrier-data-feed-without-dedicated-router/m-p/242092#M69301</link>
      <description>&lt;P&gt;For this to work your ISP has to route subnet&amp;nbsp;50.206.224.144/29 towards&amp;nbsp;40.202.237.174&lt;/P&gt;&lt;P&gt;Has this been configured in ISP routing table?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 19:47:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-carrier-data-feed-without-dedicated-router/m-p/242092#M69301</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-12-04T19:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Configure carrier data feed without dedicated router?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-carrier-data-feed-without-dedicated-router/m-p/242117#M69304</link>
      <description>&lt;P&gt;Thats's a good question..&lt;BR /&gt;I would assume the routes are in their forwarding table since I can use SNAT rules to direct traffic over each of the 6 IP addresses&amp;nbsp;which I visually confirmed&amp;nbsp;with showmyip.net.&amp;nbsp; The response page wouldn't show if the route was missing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inbound (DNAT) is being tested&amp;nbsp;using the default IIS page with the system used in the outbound test.&amp;nbsp; Requests to the default page time out.&amp;nbsp; The security and NAT rules never increment. &amp;nbsp;Both rules&amp;nbsp;at the tops of their respective lists.&amp;nbsp; The page displays when requested from systems on the local LAN.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 21:29:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-carrier-data-feed-without-dedicated-router/m-p/242117#M69304</guid>
      <dc:creator>BDS_Vince</dc:creator>
      <dc:date>2018-12-04T21:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: Configure carrier data feed without dedicated router?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configure-carrier-data-feed-without-dedicated-router/m-p/242131#M69306</link>
      <description>&lt;P&gt;This is a typical service provider setup expecting a packet based router as the customer device on the site.&amp;nbsp; The second range would be on the router interface that connects then to the customer firewall (PAN) using that on the WAN firewall port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As noted the second range is routed to the first ip address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you should be able to use the full routed /29 as dnat or snat addresses on the PAN using the first /30 as you are.&amp;nbsp; And your snat test does validate this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So there is an error in your security or NAT policy on the PAN.&amp;nbsp; Verified by the lack of hits with your known traffic.&amp;nbsp; I would start by confirming the zone to zone assignment for the addresses involved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 23:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configure-carrier-data-feed-without-dedicated-router/m-p/242131#M69306</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-12-04T23:45:16Z</dc:date>
    </item>
  </channel>
</rss>

