<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA 200 Connected to 4G Router in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306871#M79701</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130645"&gt;@Adam42&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is it a problem if the public IP is on the 4G router? Btw. are you sure your 4G modem has a public IP? The way I used these modems so far, they always got a private IP ln the external interface and on provider side ther is carrier grade NAT for connections towards the internet.&lt;/P&gt;&lt;P&gt;Anyway, for GP LSVPN you don't need a public IP on your spoke firewall. Only the hub will need a public IP to receive the connections.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jan 2020 19:25:46 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2020-01-15T19:25:46Z</dc:date>
    <item>
      <title>PA 200 Connected to 4G Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306767#M79680</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;We currently have a primary direct internet from the ISP to the Palo Alto PA-200 configured with LSVPN .&lt;/P&gt;&lt;P&gt;As we plan to have a secondary Internet, we want to connect the Palo Alto PA-200 with 4G Router using LSVPN as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is the public IP address is assigned to the 4G router and we'll connect it via LAN With PA-200 as the diagram illustrates below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4G-PA200.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23464i18318E2801335BC3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="4G-PA200.jpg" alt="4G-PA200.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;How can Configure the PA-200 to implement the LSVPN as a client&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cordially&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 08:09:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306767#M79680</guid>
      <dc:creator>Adam42</dc:creator>
      <dc:date>2020-01-15T08:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: PA 200 Connected to 4G Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306814#M79691</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Does the 4G router have the ability to just pass all traffic without performing any other tasks or to be a transparent device so the PAN could have the public IP? Meaning the PA-200 should be able to make the request to the core of the LSVPN and make the connection. Is this not working as designed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 15:13:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306814#M79691</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-01-15T15:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: PA 200 Connected to 4G Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306871#M79701</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130645"&gt;@Adam42&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is it a problem if the public IP is on the 4G router? Btw. are you sure your 4G modem has a public IP? The way I used these modems so far, they always got a private IP ln the external interface and on provider side ther is carrier grade NAT for connections towards the internet.&lt;/P&gt;&lt;P&gt;Anyway, for GP LSVPN you don't need a public IP on your spoke firewall. Only the hub will need a public IP to receive the connections.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 19:25:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306871#M79701</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-01-15T19:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: PA 200 Connected to 4G Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306875#M79703</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;FONT color="#000000"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Which configuration should I do to make the router works transparent in order to carry&amp;nbsp;the public IP address to the firewall? If I configure the DMZ IP on the router by assigning the IP address of the interface of the firewall PA200 will make it transparent?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Which configuration should I put on the firewall (spoke)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thank you&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 08:04:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306875#M79703</guid>
      <dc:creator>Adam42</dc:creator>
      <dc:date>2020-01-16T08:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: PA 200 Connected to 4G Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306939#M79722</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Back in the day when i was doing this, there was a setting in the 4g router that allowed it to be transparent and it would pass the public IP to the attached device/firewall. While I dont know what or if there is that in the device you are using, you might want to reach out to the vendor and check. However like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;pointed out. it might not be required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 15:23:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/306939#M79722</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-01-16T15:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA 200 Connected to 4G Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/307171#M79761</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your answer, Well i'm using Huawei AR160 series .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Hub administrators are requesting the&amp;nbsp; public ip and its Gatway but the 4G providers has just offered One Public IP /32 With NAT .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2020 08:54:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/307171#M79761</guid>
      <dc:creator>Adam42</dc:creator>
      <dc:date>2020-01-19T08:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA 200 Connected to 4G Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/347008#M86570</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You just need to NAT inbound ports from the 4G router to the Palo IP.&amp;nbsp; Or simpler if you just set a DMZ host on the 4G router to send all traffic to the PA.&lt;/P&gt;&lt;P&gt;The ISP however will need to map a public address and inbound ports as the carriers usually only allocate you a private address.&amp;nbsp; I've just bought a international SIM card that does this.&amp;nbsp; They basically assign me a static public address their end, and it NATs through their cell provider VPN to the private IP on my router.&amp;nbsp; I need to arrange with them what ports they pass inbound (which is good as it filters out port scans etc but bad as if I want to add a new service I have to ask them)&lt;/P&gt;&lt;P&gt;Ports for LSVPN are tcp/443 and udp/4501&lt;/P&gt;&lt;P&gt;That router then NAT's all inbound to the ip on the palo alto.&amp;nbsp; The palo alto is configured with a private address but it doesnt matter as long as your public IP is used for LSVPN inbound.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is a remote office then you don't need any of the inbound NAT's setup as its a one way connection.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 20:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-200-connected-to-4g-router/m-p/347008#M86570</guid>
      <dc:creator>Berite</dc:creator>
      <dc:date>2020-09-04T20:44:54Z</dc:date>
    </item>
  </channel>
</rss>

