<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Configuration to access Remote Desktop in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278218#M75572</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;RDP is unsecure and I do not recommend you use it over the internet. Please use a secure channel like one Bpry suggeted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jul 2019 21:40:32 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-07-22T21:40:32Z</dc:date>
    <item>
      <title>NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278056#M75549</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We need to configure an input rule to authorize an public IP address to access at one of our virtual machine on our subnet.&lt;/P&gt;&lt;P&gt;Concretely, I need to authorize public IP address 195.193.194.195 access directly to our virtual machine with the private IP 192.168.1.1 on the port 3389 (Remote Desktop) only via our public IP address (82.83.84.85).&lt;/P&gt;&lt;P&gt;I configured a NAT rule but it didn't work. May be I doing something wrong ?&lt;/P&gt;&lt;P&gt;Can you help us about this topic ?&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 11:09:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278056#M75549</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2019-07-22T11:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278063#M75550</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79471"&gt;@feelgood&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope you have configured the NAT and security rule properly. refer below doc for help.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/networking/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/networking/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 11:30:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278063#M75550</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-07-22T11:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278064#M75551</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your answer, I go test that.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 11:48:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278064#M75551</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2019-07-22T11:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278085#M75554</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79471"&gt;@feelgood&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;While this certainly works I would question why you wouldn't simply give whoever's needs access to this device access through the built in GlobalProtect VPN solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are still exposing this desktop to the outside world. You might be limiting it via a security policy but the NAT statement is still there. To avoid issues due to a misconfiguration I would recommend against your current approach.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 12:25:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278085#M75554</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-22T12:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278100#M75557</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have already GlobalProtect configured on our PanOS but it's for our users. This NAT configuration is for a partner who needs to access an environnement via our public IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We don't want grant access at this partner on our VPN access because it's not partitionned correctly at this time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, the only solution I founded it's this NAT rules restricted on the IP address of this partner.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 12:41:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278100#M75557</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2019-07-22T12:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278101#M75558</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79471"&gt;@feelgood&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is a "quick" solution to the problem, but I would seriously look at getting GlobalProtect in a good working state to allow Vendor solutions access to select machines rather than a NAT solution. You already have GlobalProtect exposed to the outside and this solution is just adding another entry point into your network. It might be secure by a source address, but one small configuration mistake would open it up to anyone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my two cents, clearly either is a viable solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 12:51:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278101#M75558</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-22T12:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278111#M75560</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your advices. We need to grant access to partner this week so I need a quick solution. But we are aware that is a dirty solution and we need to more secure our GlobalProtect access in the future.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 13:06:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278111#M75560</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2019-07-22T13:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278218#M75572</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;RDP is unsecure and I do not recommend you use it over the internet. Please use a secure channel like one Bpry suggeted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 21:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278218#M75572</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-07-22T21:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278301#M75589</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I reconsider my position and you're wright, it's so dangerous to expose RDP on Internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, I search other solution without VPN (for the moment). May be a VNC solution.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 08:09:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278301#M75589</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2019-07-23T08:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278353#M75592</link>
      <description>&lt;P&gt;Finally, I think to segregate subnets ont my GlobalProtect configuration but I have a question : Can I apply different segregation by users or users group ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="capture.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20738i967C4D02527D8DD9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="capture.png" alt="capture.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 13:28:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278353#M75592</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2019-07-23T13:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration to access Remote Desktop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278453#M75627</link>
      <description>&lt;P&gt;Exposing RDP = BAD BAD BAD!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use a product designed to do this that can open via a proxy service.&amp;nbsp; Something like teamview or a similar solution that includes some kind of authentication/authorization.&amp;nbsp; This avoids all the NAT goofyness and security implications you are getting yourself into as well.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 17:46:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-configuration-to-access-remote-desktop/m-p/278453#M75627</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-07-23T17:46:08Z</dc:date>
    </item>
  </channel>
</rss>

