<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 1:1 destination nat mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/1-1-destination-nat-mapping/m-p/296728#M77993</link>
    <description>&lt;P&gt;Thank you for the links!&lt;/P&gt;</description>
    <pubDate>Wed, 06 Nov 2019 15:52:36 GMT</pubDate>
    <dc:creator>grenzi</dc:creator>
    <dc:date>2019-11-06T15:52:36Z</dc:date>
    <item>
      <title>1:1 destination nat mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-1-destination-nat-mapping/m-p/296679#M77988</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; does anybody know if it is possible to write a single destination NAT policy in order to map ip addresses from a given range/network to a corresponding range/network of the same size preserving the host portion of the address? I try to explain with an example. I would like to translate packets destined to 192.168.10.0/24 with address in 10.168.10.0/24 in this way:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.10.1 --&amp;gt; 10.168.10.1&lt;/P&gt;&lt;P&gt;192.168.10.2 --&amp;gt; 10.168.10.2&lt;/P&gt;&lt;P&gt;192.168.10.3 --&amp;gt; 10.168.10.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...and so on, without configuring 254 static destination nat policies.&lt;/P&gt;&lt;P&gt;Anybody knows?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 13:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-1-destination-nat-mapping/m-p/296679#M77988</guid>
      <dc:creator>grenzi</dc:creator>
      <dc:date>2019-11-06T13:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: 1:1 destination nat mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-1-destination-nat-mapping/m-p/296695#M77989</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/61214"&gt;@grenzi&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;Use the Static IP mapping type to translate an entire address range to a specific address range, a one-to-one mapping&lt;/SPAN&gt;&lt;/SPAN&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out the following KB:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhwCAC" target="_blank" rel="noopener"&gt;Source NAT Translation Types and Typical Use Cases&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT &amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;
&lt;P&gt;Just noticed that you talked about destination NAT ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can configure ranges like this example&amp;nbsp; :&lt;/P&gt;
&lt;P&gt;Source: 192.168.1.1-192.168.1.4&lt;/P&gt;
&lt;P&gt;Destination: 2.2.2.1-2.2.2.4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As explained here :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/nat/source-nat-and-destination-nat/destination-nat.html" target="_self"&gt;destination-nat&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 06 Nov 2019 14:57:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-1-destination-nat-mapping/m-p/296695#M77989</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-11-06T14:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: 1:1 destination nat mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-1-destination-nat-mapping/m-p/296728#M77993</link>
      <description>&lt;P&gt;Thank you for the links!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 15:52:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-1-destination-nat-mapping/m-p/296728#M77993</guid>
      <dc:creator>grenzi</dc:creator>
      <dc:date>2019-11-06T15:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: 1:1 destination nat mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/1-1-destination-nat-mapping/m-p/386623#M90282</link>
      <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;&lt;P&gt;When implementing 1:1 static NAT for an IP address range, are there anythings I should consider?&amp;nbsp; For example, is there maximum number of NAT?&amp;nbsp; Do you recommend do static NAT for /16 IP address range?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Wsing&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 16:11:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/1-1-destination-nat-mapping/m-p/386623#M90282</guid>
      <dc:creator>wsing</dc:creator>
      <dc:date>2021-02-18T16:11:52Z</dc:date>
    </item>
  </channel>
</rss>

