<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure PAN to allow for SFTP traffic over public ip in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253089#M71912</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configuration to allow aftp from dmz to internet .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;KM&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:13:18 GMT</pubDate>
    <dc:creator>KarthikMuthukrishnan</dc:creator>
    <dc:date>2019-03-11T12:13:18Z</dc:date>
    <item>
      <title>How to configure PAN to allow for SFTP traffic over public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/252057#M71669</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to configure PAN to allow for the SFTP traffic over public ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;KM&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2019 09:54:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/252057#M71669</guid>
      <dc:creator>KarthikMuthukrishnan</dc:creator>
      <dc:date>2019-03-03T09:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure PAN to allow for SFTP traffic over public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/252088#M71674</link>
      <description>&lt;P&gt;From internal to the internet or from the internet to a host in your internal network?&lt;/P&gt;&lt;P&gt;In both cases you need a NAT rule and a security policy rule that allows ssh.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2019 21:06:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/252088#M71674</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-03-03T21:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure PAN to allow for SFTP traffic over public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/252111#M71677</link>
      <description>&lt;P&gt;Thanks for your reply , I am new to this process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Working on a task to migrate existing DMZ traffic from ASA to Palo alto.&lt;/P&gt;&lt;DIV class="theme1"&gt;&lt;DIV class="content-wrapper"&gt;&lt;DIV&gt;&lt;DIV class="detailview fw whitebg display-table"&gt;&lt;DIV class="content-panel"&gt;&lt;DIV class="content-panel-inner"&gt;&lt;DIV class="left-panel pos-rel"&gt;&lt;DIV class="left-panel-inner"&gt;&lt;DIV&gt;&lt;DIV class="cs-wrapper-outer"&gt;&lt;DIV class="cs-wrapper"&gt;&lt;DIV class="content-section"&gt;&lt;DIV&gt;&lt;DIV class="accordion-log"&gt;&lt;DIV class="panel-group"&gt;&lt;DIV class="panel panel-base"&gt;&lt;DIV class="panel-collapse collapse in"&gt;&lt;DIV class="pos-rel"&gt;&lt;DIV class="panel-body p0"&gt;&lt;DIV class="p10 atp-container-target atp-container m0"&gt;&lt;DIV class="pt10 pb10"&gt;&lt;DIV&gt;I was told to Configure the PAN to allow for the SFTP traffic over an public IP, no idea about it.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;that means redirecting the traffic to public ip ? please give me details configure note.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks in advance&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;KM&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 04 Mar 2019 06:49:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/252111#M71677</guid>
      <dc:creator>KarthikMuthukrishnan</dc:creator>
      <dc:date>2019-03-04T06:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure PAN to allow for SFTP traffic over public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253016#M71892</link>
      <description>&lt;P&gt;What exactly do you try to configure? Allow sftp from internal/dmz to the internet or from the internet to an internal or dmz server? If from internet, does your server have a punlic or private IP?&lt;/P&gt;&lt;P&gt;In order to let the community help you need to give us some more informations about the situation.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 17:43:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253016#M71892</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-03-09T17:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure PAN to allow for SFTP traffic over public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253089#M71912</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configuration to allow aftp from dmz to internet .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;KM&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:13:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253089#M71912</guid>
      <dc:creator>KarthikMuthukrishnan</dc:creator>
      <dc:date>2019-03-11T12:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure PAN to allow for SFTP traffic over public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253117#M71923</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/88667"&gt;@KarthikMuthukrishnan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does your DMZ server have a private IP? If yes then you need a security policy rule that allows ssh from your DMZ server zone and IP to the internet. In addition you need a NAT rule with the source your dmz server zone/ip as source and the internet zone as destination. In the translated address tab configure dynamic ip and port and interface IP. There you chose your internet facing interface and the corresponding IP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:15:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253117#M71923</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-03-11T17:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure PAN to allow for SFTP traffic over public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253691#M72021</link>
      <description>&lt;P&gt;&amp;nbsp;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did create a NAT policy where both source and destination are untrust zones, source - any, destination is public ip and destination address translation is private IP ( sftp Ip ) . hope I am right.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy :&lt;/P&gt;&lt;P&gt;source : untrust , ip address : any&amp;nbsp;&lt;/P&gt;&lt;P&gt;destination : trust , ip address :not sure which IP i sho uld give&amp;nbsp; sftp private IP or public ip .&lt;/P&gt;&lt;P&gt;application : any , service : sftp&amp;nbsp; , action allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;KM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 12:20:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253691#M72021</guid>
      <dc:creator>KarthikMuthukrishnan</dc:creator>
      <dc:date>2019-03-14T12:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure PAN to allow for SFTP traffic over public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253818#M72061</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Check out this article, it may help out:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllzCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllzCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 21:12:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/253818#M72061</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-14T21:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure PAN to allow for SFTP traffic over public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/254058#M72133</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the link... I read few documents&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like this will exactly serve my purpose.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am adding new external ip (public ip)&amp;nbsp; and point it to the existing sftp ip (private ip ) . Correct me if I am wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping&amp;nbsp;" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 12:49:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-pan-to-allow-for-sftp-traffic-over-public-ip/m-p/254058#M72133</guid>
      <dc:creator>KarthikMuthukrishnan</dc:creator>
      <dc:date>2019-03-18T12:49:32Z</dc:date>
    </item>
  </channel>
</rss>

