<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PBF with NAT, how does it works? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/10260#M7541</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to document , if there's destination NAT , there'll be second routing lookup to decide outbound zone &amp;amp; interface. But I'm very confused when there's routing and PBF together, In the second routing lookup, how does PBF rule work? Does PBF work based on Pre-NAT destination address or Post-NAT destination address? According to document at the second lookup process works based on POST-NAT destination address, that means if the routing table works fine, it should follow routing table lookup result. But in my customers networks it doesn't look like that.. Using PBF and U-Turn NAT together is really kind of a mess.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Sep 2013 05:27:01 GMT</pubDate>
    <dc:creator>JTR</dc:creator>
    <dc:date>2013-09-06T05:27:01Z</dc:date>
    <item>
      <title>PBF with NAT, how does it works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/10260#M7541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to document , if there's destination NAT , there'll be second routing lookup to decide outbound zone &amp;amp; interface. But I'm very confused when there's routing and PBF together, In the second routing lookup, how does PBF rule work? Does PBF work based on Pre-NAT destination address or Post-NAT destination address? According to document at the second lookup process works based on POST-NAT destination address, that means if the routing table works fine, it should follow routing table lookup result. But in my customers networks it doesn't look like that.. Using PBF and U-Turn NAT together is really kind of a mess.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2013 05:27:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/10260#M7541</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-09-06T05:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: PBF with NAT, how does it works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/10261#M7542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would any of these docs be of any help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Understanding PAN-OS NAT&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" data-containerid="2021" data-containertype="14" data-objectid="1517" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;https://live.paloaltonetworks.com/docs/DOC-1517&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet Flow in PAN-OS&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="1628" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1628"&gt;https://live.paloaltonetworks.com/docs/DOC-1628&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2013 05:34:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/10261#M7542</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-09-06T05:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: PBF with NAT, how does it works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/10262#M7543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PBF lookup happens in pre-NAT IP address. Also in PAN firewall NAT evaluate at first with original IP but Apply at the end of flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Packet flow on PAN firewall:-&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="packet-flow.JPG.jpg" class="jive-image" height="333" src="https://live.paloaltonetworks.com/legacyfs/online/8069_packet-flow.JPG.jpg" style="width: 496px; height: 333.1221122112211px;" width="496" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Few more information regarding the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1507"&gt;Fowarding&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3241"&gt;Testing Security, NAT and PBF Rules via the CLI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3349"&gt;Inbound NAT Policy with Outbound PBF Causing IP-Spoofing Drops&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/26245"&gt;NAT and Security Policies, PBF Failover and Symmetric Return - Dual ISP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1628"&gt;Packet Flow in PAN-OS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2013 06:23:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/10262#M7543</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-09-06T06:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: PBF with NAT, how does it works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/10263#M7544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot . I'll read these document. Hava a nice day!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2013 07:05:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/10263#M7544</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-09-06T07:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: PBF with NAT, how does it works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/585352#M116868</link>
      <description>&lt;P&gt;Sorry to revive this 10 years later. Documentation is not specific enough for me. But in my experience:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp;If there is Dest NAT there will be a second routing lookup, that will include a second PBF lookup. To be clear, the moment there is Dest NAT it will ignore all previous PBF/routing lookups and evaluate both again.&lt;/LI&gt;
&lt;LI&gt;The IP addresses used in the second routing/PBF lookup are: PRE-NAT source, and POST-NAT destination.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I said, official documentation is quite good, but I missed those specific issues.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 15:02:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-nat-how-does-it-works/m-p/585352#M116868</guid>
      <dc:creator>AGrijalba</dc:creator>
      <dc:date>2024-04-30T15:02:27Z</dc:date>
    </item>
  </channel>
</rss>

