<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Assign Secondary Public IP address in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/251073#M71391</link>
    <description>&lt;P&gt;I assigned the ip to a loopback interface then created NAT and Security policy seems to work just fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 23 Feb 2019 18:48:30 GMT</pubDate>
    <dc:creator>msteinbach</dc:creator>
    <dc:date>2019-02-23T18:48:30Z</dc:date>
    <item>
      <title>Assign Secondary Public IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/250868#M71338</link>
      <description>&lt;P&gt;We needed additional Public IP for SIP and web server hosting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My original IP was a single IP example "67.173.83.121\30".&amp;nbsp; The ISP gave us&amp;nbsp;another range to use 67.173.75.73\28.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can i add&amp;nbsp;67.173.75.73\28 range to my PA so I can apply NAT rules to it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Loopback interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 12:09:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/250868#M71338</guid>
      <dc:creator>msteinbach</dc:creator>
      <dc:date>2019-02-22T12:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Assign Secondary Public IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/250900#M71348</link>
      <description>&lt;P&gt;I've not done this, but I think you'd just need to have it assigned to the Physical or AE of your "untrust" / INet facing side of your FW those two IPs as well as add the IPs you want to your NAT policy.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 13:25:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/250900#M71348</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-02-22T13:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: Assign Secondary Public IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/251073#M71391</link>
      <description>&lt;P&gt;I assigned the ip to a loopback interface then created NAT and Security policy seems to work just fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Feb 2019 18:48:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/251073#M71391</guid>
      <dc:creator>msteinbach</dc:creator>
      <dc:date>2019-02-23T18:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Assign Secondary Public IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/251075#M71392</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82393"&gt;@msteinbach&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your ISP gave you this segment and have proper route to this network towards your firewall,As of my best knowledge, you need not to have this IP in firewall. you can have proper NAT and security policy. everything will work. need not to wast one public IP.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Feb 2019 06:30:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/251075#M71392</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-02-24T06:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Assign Secondary Public IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/251572#M71537</link>
      <description>&lt;P&gt;There is a way without using a loopback with one of your public IP addresses on it. As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;&amp;nbsp; says, that uses an IP address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the steps the PA takes when evaluating traffic is the existence of a route to the destination. If the route doesn't exist, the traffic is dropped without further processing. The route just has to exist, it doesn't have to necessarily be valid.&lt;/P&gt;&lt;P&gt;So you can set up a null route for the new subnet which will allow the packet flow to continue.&amp;nbsp; I have done this method several times and it works well.&lt;/P&gt;&lt;P&gt;Since you created a loopback, a connected route will exist for that subnet and permit the flow to continue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the document that explains the need for the existence of the route.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0" target="_self"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 19:17:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/251572#M71537</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-27T19:17:13Z</dc:date>
    </item>
  </channel>
</rss>

