<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow inbound concetion to multiple servers  from single public ip in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-inbound-concetion-to-multiple-servers-from-single-public/m-p/253976#M72112</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;You will need a NAT for each server and just specify the 'Service' (service = port).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Mar 2019 19:45:50 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-03-15T19:45:50Z</dc:date>
    <item>
      <title>Allow inbound concetion to multiple servers  from single public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-inbound-concetion-to-multiple-servers-from-single-public/m-p/253961#M72107</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have vendor device with public ip in internet.&lt;/P&gt;&lt;P&gt;IT need to talk to multiple servers inside the company network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all the internal servers have private ip and connection need to come on different port numbers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently I am allowing the incoming connection from vendor to one of our public ip address and using static nat translation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for destination address.&lt;/P&gt;&lt;P&gt;how can i do destination nat&amp;nbsp; translation the single public ip address of firewall to the multiple ports and addresses?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 18:21:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-inbound-concetion-to-multiple-servers-from-single-public/m-p/253961#M72107</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-15T18:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Allow inbound concetion to multiple servers  from single public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-inbound-concetion-to-multiple-servers-from-single-public/m-p/253976#M72112</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;You will need a NAT for each server and just specify the 'Service' (service = port).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 19:45:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-inbound-concetion-to-multiple-servers-from-single-public/m-p/253976#M72112</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-15T19:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Allow inbound concetion to multiple servers  from single public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-inbound-concetion-to-multiple-servers-from-single-public/m-p/253979#M72113</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;While what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp; mentioned is right; I'd be amiss if I didn't mention this is a&amp;nbsp;&lt;EM&gt;terrible&amp;nbsp;&lt;/EM&gt;security practice. You should be giving the IT folks access to a VPN (like the built-in GlobalProtect), limiting their access to the servers in question, and then letting them work like that. Exposing something to the outside via a NAT rule, even when properly restricted with a security policy and source addresses, is a terrible security practice.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 20:37:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-inbound-concetion-to-multiple-servers-from-single-public/m-p/253979#M72113</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-03-15T20:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Allow inbound concetion to multiple servers  from single public ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-inbound-concetion-to-multiple-servers-from-single-public/m-p/254027#M72124</link>
      <description>&lt;DIV class="lia-page"&gt;&lt;CENTER&gt;&lt;DIV class="MinimumWidthContainer"&gt;&lt;DIV class="min-width-wrapper"&gt;&lt;DIV class="min-width"&gt;&lt;DIV class="lia-content"&gt;&lt;DIV class="lia-quilt lia-quilt-forum-topic-page lia-quilt-layout-two-column-main-side lia-top-quilt"&gt;&lt;DIV class="lia-quilt-row lia-quilt-row-main"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-18 lia-quilt-column-left lia-quilt-column-main-content"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-left"&gt;&lt;DIV class="lia-component-message-list"&gt;&lt;DIV class="linear-message-list message-list"&gt;&lt;DIV class="lia-linear-display-message-view"&gt;&lt;DIV&gt;&lt;DIV class="lia-message-view message-uid-254026"&gt;&lt;DIV&gt;&lt;DIV class="lia-js-resize-images lia-component-forums-widget-board-message-view"&gt;&lt;DIV&gt;&lt;DIV class="lia-message-board lia-panel-message lia-js-data-messageUid-254026"&gt;&lt;DIV class="lia-panel-message-content"&gt;&lt;DIV class="lia-decoration-border"&gt;&lt;DIV class="lia-decoration-border-content"&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class="lia-quilt lia-quilt-forum-message lia-quilt-layout-forum-message"&gt;&lt;DIV class="lia-quilt-row lia-quilt-row-forum-message-main"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-20 lia-quilt-column-right lia-quilt-column-main-right"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-right"&gt;&lt;DIV class="lia-message-body lia-component-body"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;I agree with you.&lt;/P&gt;&lt;P&gt;But in current scenario the end device does not support support windows it runs on linux and current version of it does not&lt;/P&gt;&lt;P&gt;support global protect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as we are migrating this from Cisco ASA it is better protected with PA.&lt;/P&gt;&lt;P&gt;Also then end device only talks to few servers on specfic port.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/CENTER&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 17 Mar 2019 16:40:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-inbound-concetion-to-multiple-servers-from-single-public/m-p/254027#M72124</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-17T16:40:57Z</dc:date>
    </item>
  </channel>
</rss>

