<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSEC VPN NAT issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-nat-issue/m-p/292017#M77331</link>
    <description>&lt;P&gt;I have a VPN request where&amp;nbsp; peer's IP range is conflicting with one of my internal IP range.&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are asking me if I can do a NAT on my end to resolve it but based on my experience it must be them who should do a NAT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;please correct me if I'm wrong.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Oct 2019 20:02:11 GMT</pubDate>
    <dc:creator>SThatipelly</dc:creator>
    <dc:date>2019-10-08T20:02:11Z</dc:date>
    <item>
      <title>IPSEC VPN NAT issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-nat-issue/m-p/292017#M77331</link>
      <description>&lt;P&gt;I have a VPN request where&amp;nbsp; peer's IP range is conflicting with one of my internal IP range.&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are asking me if I can do a NAT on my end to resolve it but based on my experience it must be them who should do a NAT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;please correct me if I'm wrong.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 20:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-nat-issue/m-p/292017#M77331</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2019-10-08T20:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN NAT issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-nat-issue/m-p/292045#M77332</link>
      <description>&lt;P&gt;Here is the way I would recommend that you do it...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scenario is overlapping subnets on both side of IPSec Tunnel.&lt;/P&gt;&lt;P&gt;Both sides need to NAT, to give the remote sides a different appearance/subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpnnat.png" style="width: 892px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21732iB3E9C946086C8884/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vpnnat.png" alt="vpnnat.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) A different option may be (not sure) to only SNAT from the remote side, inbound to your environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Different from the top example.&lt;/P&gt;&lt;P&gt;Both remote and local sites have overlapping subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when traffic from remote side enters your FW, you SNAT it, and send it, inbound to your network, with bidirectional enabled.&lt;/P&gt;&lt;P&gt;Now a user/server, etc, will send back traffic to the SNAT'd address, and your FW will strip off the SNAT and send to the correct source address, across the VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions??? &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2ndoption.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21733i19F8DC26A071FB6E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2ndoption.png" alt="2ndoption.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 01:36:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-nat-issue/m-p/292045#M77332</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-10-09T01:36:58Z</dc:date>
    </item>
  </channel>
</rss>

