<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Natting to ip address which is not binded to any interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314788#M81164</link>
    <description>&lt;P&gt;If you are doing a source NAT with an address of&amp;nbsp;&lt;SPAN&gt;200.0.0.1, but this is not the subnet between your firewall and WAN router (R2).&amp;nbsp; How are you going to get a reply back from R2 like this?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Mar 2020 19:34:00 GMT</pubDate>
    <dc:creator>OwenFuller</dc:creator>
    <dc:date>2020-03-05T19:34:00Z</dc:date>
    <item>
      <title>Natting to ip address which is not binded to any interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314353#M81100</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;I want to nat traffic going from dmz zone to wan zone. I want to nat ip (172.16.16.16&amp;amp;172.16.17.17-dmz zone) to use nat ip 200.0.0.1 which is not configured to any interface. I am unable to perform this. Please find below snap.&lt;/P&gt;&lt;P&gt;1)Interface IP addresses.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nitesharbale_0-1583322314964.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24223i9880503D2C2102F6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="nitesharbale_0-1583322314964.png" alt="nitesharbale_0-1583322314964.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2)NAT rule&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nitesharbale_1-1583322411216.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24224iB3868B579B9B9FB2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="nitesharbale_1-1583322411216.png" alt="nitesharbale_1-1583322411216.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3)Security Policy&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nitesharbale_2-1583322611401.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24225iE29A03C3B6422682/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="nitesharbale_2-1583322611401.png" alt="nitesharbale_2-1583322611401.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4)Topology&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nitesharbale_0-1583322960961.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24226i20A45350CAE816C1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="nitesharbale_0-1583322960961.png" alt="nitesharbale_0-1583322960961.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On R2 when i debug ip address i can see 200.0.0.1 ip but from R3 i cannot telnet&lt;/P&gt;&lt;P&gt;Please let me know what am i missing ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 11:58:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314353#M81100</guid>
      <dc:creator>nitesharbale</dc:creator>
      <dc:date>2020-03-04T11:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Natting to ip address which is not binded to any interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314368#M81105</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134725"&gt;@nitesharbale&lt;/a&gt;What are you seeing under traffic logs? It is matching security policy and NAT, also is traffic going on correct WAN interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where both these subnet resides as DMZ subnet configured on firewall is 172.16.1.0/24 and below server IP belongs to different subnets?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have reverse routes on firewall for IPs 172.16.16.16&amp;amp;172.16.17.17 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 13:22:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314368#M81105</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-03-04T13:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: Natting to ip address which is not binded to any interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314374#M81109</link>
      <description>&lt;P&gt;Hi Mayur,&lt;/P&gt;&lt;P&gt;Please find the answers below. Let me know if anything else required&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q1)What are you seeing under traffic logs? It is matching security policy and NAT, also is traffic going on correct WAN interface?&lt;/P&gt;&lt;P&gt;Ans&amp;nbsp; i cannot see traffic logs. i think i requires license. There is single WAN interface which is connected to R2. Security policy and nat rule are in snap posted earlier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2)Where both these subnet resides as DMZ subnet configured on firewall is 172.16.1.0/24 and below server IP belongs to different subnets?&lt;/P&gt;&lt;P&gt;172.16.1.2/24--R3 interface ip connected to PA , (172.16.16.16/32, 172.16.17.17/32---R3 loopback) . All are in same zone i.e DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3)Do you have reverse routes on firewall for IPs 172.16.16.16&amp;amp;172.16.17.17 ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nitesharbale_0-1583330973400.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24227i5810A49BC888688C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="nitesharbale_0-1583330973400.png" alt="nitesharbale_0-1583330973400.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 14:27:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314374#M81109</guid>
      <dc:creator>nitesharbale</dc:creator>
      <dc:date>2020-03-04T14:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Natting to ip address which is not binded to any interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314381#M81112</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134725"&gt;@nitesharbale&lt;/a&gt;Please verify traffic using test command and see if matching correct Security policy, NAT and Route.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 15:04:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314381#M81112</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-03-04T15:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: Natting to ip address which is not binded to any interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314753#M81156</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;This is possible as long as the PAN knows where to route the traffic. I didnt review the config, but as stated, check the logs and see where/if the policies are getting applied and or traffic getting blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 18:14:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314753#M81156</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-03-05T18:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Natting to ip address which is not binded to any interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314788#M81164</link>
      <description>&lt;P&gt;If you are doing a source NAT with an address of&amp;nbsp;&lt;SPAN&gt;200.0.0.1, but this is not the subnet between your firewall and WAN router (R2).&amp;nbsp; How are you going to get a reply back from R2 like this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 19:34:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314788#M81164</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-03-05T19:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: Natting to ip address which is not binded to any interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314796#M81166</link>
      <description>&lt;P&gt;Do you have a route on R2 pointing back to the PAN with this address?&amp;nbsp; Also, since the IP has no interface associated with it you may have to put in what I call a "ghost route" to make sure your zones align properly.&amp;nbsp; Add a route with an interface value and next hop value of "none" to assign the proper zone.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 20:25:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-to-ip-address-which-is-not-binded-to-any-interface/m-p/314796#M81166</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2020-03-05T20:25:12Z</dc:date>
    </item>
  </channel>
</rss>

