<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do I need a NAT for traffic to pass?? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262386#M74348</link>
    <description>&lt;P&gt;Correct Layer 3 setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see the traffic in the logs but I am only seeing "aged-out".&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 May 2019 12:16:14 GMT</pubDate>
    <dc:creator>Stevenjwilliams83</dc:creator>
    <dc:date>2019-05-28T12:16:14Z</dc:date>
    <item>
      <title>Do I need a NAT for traffic to pass??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262313#M74342</link>
      <description>&lt;P&gt;I have an SD-WAN device at my internet edge that will be doing the NATing for the network. This is so that the device can decide which of 3 ISPs to use to forward traffic. My Palo Altos sit behind this device and will do the firewalling and URL filtering. I did not deploy in vwire mode, I cant seem to get traffic to pass through so my quesiton is do I need a nat statement or something regardless of what my SD-WAN device is doing?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2019 21:08:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262313#M74342</guid>
      <dc:creator>Stevenjwilliams83</dc:creator>
      <dc:date>2019-05-27T21:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need a NAT for traffic to pass??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262379#M74347</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112548"&gt;@Stevenjwilliams83&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it a L3 setup ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT shouldn't be required if you're just passing through the Palo Alto Networks device and you're performing NAT on another device although some additional info on your setup could be useful.&lt;/P&gt;
&lt;P&gt;Do you see traffic ingressing and egressing the correct interface ? Are you seeing any return traffic ? Are you allowing the traffic and is your policy being hit ? Are you seeing any drops ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 28 May 2019 10:12:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262379#M74347</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-05-28T10:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need a NAT for traffic to pass??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262386#M74348</link>
      <description>&lt;P&gt;Correct Layer 3 setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see the traffic in the logs but I am only seeing "aged-out".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 12:16:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262386#M74348</guid>
      <dc:creator>Stevenjwilliams83</dc:creator>
      <dc:date>2019-05-28T12:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need a NAT for traffic to pass??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262407#M74353</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112548"&gt;@Stevenjwilliams83&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm suspecting asymmetric traffic.&amp;nbsp; Is it possible that your return traffic is using a different route ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 14:58:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262407#M74353</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-05-28T14:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need a NAT for traffic to pass??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262408#M74354</link>
      <description>&lt;P&gt;Negative, only path in and one path out.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 14:58:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262408#M74354</guid>
      <dc:creator>Stevenjwilliams83</dc:creator>
      <dc:date>2019-05-28T14:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need a NAT for traffic to pass??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262439#M74362</link>
      <description>&lt;P&gt;What subnets do you have configured on your "WAN" port (connected to the SD-WAN device) and your "LAN" port?&amp;nbsp; Are they different?&amp;nbsp; Do you have the SD-WAN device set as the next hop in the Virtual Router for the default route (0.0.0.0/0)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For a strictly L3 routing setup, you don't need NAT rules.&amp;nbsp; But you do need to have your VR setup correctly to route traffic between the WAN subnet and the LAN subnet.&amp;nbsp; And you need your Zones setup, and your Security Policy using the correct Zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, we'd need to see a lot more info than you've given so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LAN interface has an IP/subnet that matches clients.&lt;/P&gt;&lt;P&gt;WAN interface has an IP/subnet that matches the private side of the SD-WAN device.&lt;/P&gt;&lt;P&gt;LAN devices --&amp;gt; default route points to LAN interface on the PA.&lt;/P&gt;&lt;P&gt;Virtual Router on the PA includes the two interfaces, has static routes that point to LAN subnet and WAN subnet via their respective physical interfaces, and has a default route that points to the SD-WAN device.&lt;/P&gt;&lt;P&gt;Security Policies allow traffic from "LAN" Zone to "WAN" Zone.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 20:47:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262439#M74362</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2019-05-28T20:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need a NAT for traffic to pass??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262533#M74382</link>
      <description>&lt;P&gt;So lets assume I am network engineer and I understand routing, because I do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eth1/1 - Zone Untrust IP:10.153.1.6/29&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AE1 - Zone Trust IP:10.153.0.1/29&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vrouter - default&lt;/P&gt;&lt;P&gt;- Static route - 0.0.0.0/0 next hop 10.153.1.1/29 (CloudGenix SD-WAN)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AE1 connected to Layer 3 Cisco 3650. Ports connected to AE1 Interfaces on vlan 3101. Cisco Switch has interface vlan 3101 IP:10.153.0.2. Default route on Cisco switch 0.0.0.0 0.0.0.0 10.153.0.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto Vrouter peering OSPF with Cisco layer 3 switch for all internal networks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eth1/1 is connected to a switch that is bridging the active/passive PAs with the CloudGenix SD-WAN device (all on vlan 3000) I created an SVI on this switch: interface vlan 3000 IP: 10.153.1.2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From firewall CLI:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@CEN-EDGE-PA-01(active)&amp;gt; ping source 10.153.1.6 host 10.153.1.2&lt;BR /&gt;PING 10.153.1.2 (10.153.1.2) from 10.153.1.6 : 56(84) bytes of data.&lt;BR /&gt;--- 10.153.1.2 ping statistics ---&lt;BR /&gt;30 packets transmitted, 0 received, 100% packet loss, time 29015ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So this is telling me the outside interface of palos cannot even get to the connected switch.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interfaces have Mgmt profile that is allowing network services SNMP and Ping&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-05-29 at 7.58.10 AM.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20219iFC57F4B2609DDD91/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-05-29 at 7.58.10 AM.png" alt="Screen Shot 2019-05-29 at 7.58.10 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy allows ICMP and traceroute.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-05-29 at 7.59.38 AM.png" style="width: 788px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20220i5F7438863C54929B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-05-29 at 7.59.38 AM.png" alt="Screen Shot 2019-05-29 at 7.59.38 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Routing says default route to SD-WAN device, routes to internal subnets are 10.153.0.2 which is SVI on cisco 3650 connected to AE1 interfaces on Palo.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 13:00:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/262533#M74382</guid>
      <dc:creator>Stevenjwilliams83</dc:creator>
      <dc:date>2019-05-29T13:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need a NAT for traffic to pass??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/263002#M74399</link>
      <description>&lt;P&gt;Does you rpolicy also allow the ping application, which is separate from ICMP (in Palo Alto terms)?&amp;nbsp; If not, then ping packets won't pass through the firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 16:05:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/263002#M74399</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2019-05-30T16:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need a NAT for traffic to pass??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/264769#M74426</link>
      <description>&lt;P&gt;The issue was an upstream issue with pretty much a Cisco Layer 2 switch between the firewall and the SDWAN device. It would appear that the palo alto MAC address timelimit is longer then a Cisco Switch and was causing issues with this scenario because production traffic wasnt passing regularly. If it was I would have never seen the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2019 15:06:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-a-nat-for-traffic-to-pass/m-p/264769#M74426</guid>
      <dc:creator>Stevenjwilliams83</dc:creator>
      <dc:date>2019-06-01T15:06:28Z</dc:date>
    </item>
  </channel>
</rss>

