<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DMZ Config for web server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244168#M69703</link>
    <description>&lt;P&gt;Thanks.&amp;nbsp; I did make the changes but tried to access my webserver without success...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One issue I see is that I can't ping the 5.5.5.174 address from either the outside or dmz zones.&amp;nbsp; I can ping the dmz default gateway(192.168.1.1) as well as my ISPs default gateway(5.5.5.169) from inside the dmz but can't ping any other outside addresses(5.5.5.174, 5.5.5.170, as well as other outside web addresses) from inside the dmz.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5.5.5.170 is my original outside interface and it has been working.&amp;nbsp; It's running my GlobalProtect and I haven't had any problems with that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Dec 2018 21:16:55 GMT</pubDate>
    <dc:creator>nmckee</dc:creator>
    <dc:date>2018-12-20T21:16:55Z</dc:date>
    <item>
      <title>DMZ Config for web server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244014#M69685</link>
      <description>&lt;P&gt;My firewall is using the following Interfaces/Zones: E1/1(5.5.5.170/29) and E1/1.1(5.5.5.174/29) are in the outside zone.&amp;nbsp; E1/2(192.168.254.252/24) is in the inside zone.&amp;nbsp; E1/8(192.168.1.1) is in DMZ zone.&amp;nbsp; E1/1 and E1/2 are connected to the mainvr virtual router.&amp;nbsp; E1/1.1 and E1/8 are connected to the DMZrouter virtual router.&amp;nbsp; I have a web server located in the DMZ zone (192.168.1.2/24) that I want a One-to-One static NAT to 5.5.5.174/29 to grant outside zone access to and from the web.&amp;nbsp; I’m not having any success.&amp;nbsp; Any help would be great.&amp;nbsp;&lt;/P&gt;&lt;P&gt;(My inside to outside traffic works fine just having problems with DMZ access from outside zone)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are my NAT/Security rules:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Outbound Nat rule:&lt;/P&gt;&lt;P&gt;Original packet:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source - DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source address - 192.168.1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination - Untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination Address – Any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Translated packet:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source translation - Static IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Translated address - &lt;SPAN&gt;5.5.5.174&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Bi-directional is not checked)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Inbound NAT rule:&lt;/P&gt;&lt;P&gt;Original packet:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source - Untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source address - Any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination - DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination Address &lt;SPAN&gt;5.5.5.174&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Translated packet:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination translation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Translated address - 192.168.1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Translated port is not entered)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Outbound Security Rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Zone - DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Address - 192.168.1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination zone - Untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination Address - Any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inbound Security Rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Zone - Untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Address - Any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination zone-Trust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination Address - &lt;SPAN&gt;5.5.5.174&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 12:36:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244014#M69685</guid>
      <dc:creator>nmckee</dc:creator>
      <dc:date>2018-12-20T12:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config for web server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244022#M69686</link>
      <description>&lt;P&gt;your inbound NAT policy needs to be untrust to untrust, your inbound security policy needs to be untrust to dmz&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 13:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244022#M69686</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-12-20T13:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config for web server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244067#M69697</link>
      <description>&lt;P&gt;You should also be able to use a single bi-directional rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;Bi-Directional&amp;nbsp; Nat rule:&lt;/P&gt;&lt;P&gt;Original packet:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source - DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source address - 192.168.1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination - Untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination Address – Any&lt;/P&gt;&lt;P&gt;Translated packet:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Translation Type - Static IP&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Translation Address -&amp;nbsp;&lt;SPAN&gt;5.5.5.174&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Bi-Directional [Tick]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 17:03:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244067#M69697</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-12-20T17:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config for web server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244168#M69703</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; I did make the changes but tried to access my webserver without success...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One issue I see is that I can't ping the 5.5.5.174 address from either the outside or dmz zones.&amp;nbsp; I can ping the dmz default gateway(192.168.1.1) as well as my ISPs default gateway(5.5.5.169) from inside the dmz but can't ping any other outside addresses(5.5.5.174, 5.5.5.170, as well as other outside web addresses) from inside the dmz.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5.5.5.170 is my original outside interface and it has been working.&amp;nbsp; It's running my GlobalProtect and I haven't had any problems with that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 21:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244168#M69703</guid>
      <dc:creator>nmckee</dc:creator>
      <dc:date>2018-12-20T21:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config for web server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244818#M69837</link>
      <description>&lt;P&gt;Thanks for the information.&amp;nbsp; The solution did work but I was still having issues with the web server but figured out that is was a DNS config issue.&amp;nbsp; All is well.&amp;nbsp; Thanks again!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 12:49:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-config-for-web-server/m-p/244818#M69837</guid>
      <dc:creator>nmckee</dc:creator>
      <dc:date>2019-01-03T12:49:49Z</dc:date>
    </item>
  </channel>
</rss>

