<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DMZ, inside, outside - is it simple thing? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/318044#M81711</link>
    <description>&lt;P&gt;Only one NAT rule&lt;/P&gt;&lt;P&gt;name: NATbase&lt;/P&gt;&lt;P&gt;src zone: inside&lt;/P&gt;&lt;P&gt;dst zone: outside&lt;/P&gt;&lt;P&gt;dest int: eth1/1&lt;/P&gt;&lt;P&gt;src addr: any&lt;/P&gt;&lt;P&gt;dst addr: any&lt;/P&gt;&lt;P&gt;service: any&lt;/P&gt;&lt;P&gt;src translation: dynamic-ip-port, eth1/1 , outside_ip&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Mar 2020 19:07:42 GMT</pubDate>
    <dc:creator>mxe2fmk</dc:creator>
    <dc:date>2020-03-23T19:07:42Z</dc:date>
    <item>
      <title>DMZ, inside, outside - is it simple thing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/317891#M81684</link>
      <description>&lt;P&gt;Hi there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a PA-200.&lt;/P&gt;&lt;P&gt;Internal net is 192.168.0.0/24 eth1/2 , inside L3 interface&amp;nbsp; (default gw) -&amp;nbsp; 192.168.0.254&lt;/P&gt;&lt;P&gt;One external ip address is using for outside inteface, eth1/1.&lt;/P&gt;&lt;P&gt;For connection to Internet I typically use pair inside-outside with:&lt;/P&gt;&lt;P&gt;1. NAT : dynamic-ip-and-port&amp;nbsp; to outside interface address nat-rule&lt;/P&gt;&lt;P&gt;2. Security policy&amp;nbsp;"allow from inside to outside , any dest address"&lt;/P&gt;&lt;P&gt;Now, I need provide access for FTP-Server. I created DMZ interface eth1/3 - 172.16.0.254/24&lt;/P&gt;&lt;P&gt;FTP-Server is directly-connected to DMZ-port and has ip 172.16.0.1&lt;/P&gt;&lt;P&gt;For this scenario i created&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. NAT : bi-directional between FTP-Server and Outside .&lt;/P&gt;&lt;P&gt;2. Security policy for Outside and DMZ.&lt;/P&gt;&lt;P&gt;What I can do as next step for provide connection between inside and DMZ?&lt;/P&gt;&lt;P&gt;I create security policy allow inside-dmz (to 172.16.0.0/24) and dmz-inside (to 192.168.0.0/24)&lt;/P&gt;&lt;P&gt;If i do ping 172.16.0.1 from 192.168.0.1 than i see that all packets are matching to first NAT-rule "inside to outside" and that is wrong way.&lt;/P&gt;&lt;P&gt;What is wrong in my steps? How I can exclude traffic from "default "NAT-rule. Althought I tryed create no-nat rule than it do not work.&lt;/P&gt;&lt;P&gt;Thank for help.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Mar 2020 14:39:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/317891#M81684</guid>
      <dc:creator>mxe2fmk</dc:creator>
      <dc:date>2020-03-22T14:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ, inside, outside - is it simple thing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/317939#M81687</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83398"&gt;@mxe2fmk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Methinks you'll be needing U-turn NAT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out the following links on the topic:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEiCAK" target="_blank" rel="noopener"&gt;HOW TO CONFIGURE U-TURN NAT&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXECA0" target="_blank" rel="noopener"&gt;DOTW: U-TURN NAT ISSUE&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=Bdbn1pbe74o" target="_blank" rel="noopener"&gt;Video tutorial: U-turn NAT&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 07:47:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/317939#M81687</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-03-23T07:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ, inside, outside - is it simple thing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/317965#M81695</link>
      <description>&lt;P&gt;your default NAT rule must be wrong&lt;/P&gt;&lt;P&gt;my guess is that you didn't add zones properly and one or all zone fields contain an ANY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your nat rules should be&lt;/P&gt;&lt;P&gt;FROM internet TO internet DO destination translation to FTP-internal&amp;nbsp; &lt;FONT color="#008080"&gt;(don't do bidirectional)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;FROM lan &amp;amp; dmz TO internet DO dynamicIP/port sourcenat&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this way your connection from 192.168 to 172.16 can never hit a NAT rule and you'll be good to go&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 12:16:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/317965#M81695</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-03-23T12:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ, inside, outside - is it simple thing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/317983#M81700</link>
      <description>&lt;P&gt;Try the following:&lt;/P&gt;&lt;P&gt;- eth1/2 IP address 192.168.0.254/24&lt;BR /&gt;- eth1/3 IP address 172.16.0.254/24&lt;BR /&gt;- Create a service group object with all the ports for the FTP service. [svc-group-ftp]&lt;BR /&gt;- FTP server's IP 172.16.0.1/24 and gateway 172.16.0.254&lt;BR /&gt;- Security rule to allow desired traffic from inside to DMZ, and from DMZ to inside. This one you have already.&lt;BR /&gt;- Source NAT rule dynamic-ip-and-port from DMZ to outside eth1/1 to enable the FTP server to access the internet. Same as the one you have for inside zone but for DMZ. You can also keep the one you have and add the DMZ zone in the src zones.&lt;BR /&gt;- Destination NAT rule for outside traffic to your DMZ&lt;BR /&gt;src zone outside, dst zone outside, dst interface eth1/1, service [svc-group-ftp], src address any, dst address [your-public-ip], src transation none, dst transation static ip 172.16.0.1&lt;BR /&gt;- Security rule to allow outside traffic to DMZ FTP server&lt;BR /&gt;src zone outside, src address any, dst zone dmz, dst address [your-public-ip], application any, service [svc-group-ftp]&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 13:46:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/317983#M81700</guid>
      <dc:creator>Mike-K</dc:creator>
      <dc:date>2020-03-23T13:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ, inside, outside - is it simple thing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/318031#M81709</link>
      <description>&lt;P&gt;I found out that U-turn NAT is possible scenario for one-zone ( inside ), and isn't for using with inside-dmz pair.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 19:01:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/318031#M81709</guid>
      <dc:creator>mxe2fmk</dc:creator>
      <dc:date>2020-03-23T19:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ, inside, outside - is it simple thing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/318044#M81711</link>
      <description>&lt;P&gt;Only one NAT rule&lt;/P&gt;&lt;P&gt;name: NATbase&lt;/P&gt;&lt;P&gt;src zone: inside&lt;/P&gt;&lt;P&gt;dst zone: outside&lt;/P&gt;&lt;P&gt;dest int: eth1/1&lt;/P&gt;&lt;P&gt;src addr: any&lt;/P&gt;&lt;P&gt;dst addr: any&lt;/P&gt;&lt;P&gt;service: any&lt;/P&gt;&lt;P&gt;src translation: dynamic-ip-port, eth1/1 , outside_ip&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 19:07:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/318044#M81711</guid>
      <dc:creator>mxe2fmk</dc:creator>
      <dc:date>2020-03-23T19:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ, inside, outside - is it simple thing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/318048#M81713</link>
      <description>&lt;P&gt;Ok, I unerstand this example.&lt;/P&gt;&lt;P&gt;Could You please additional moment - what's about NAT rule "inside to outside"?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 19:13:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-inside-outside-is-it-simple-thing/m-p/318048#M81713</guid>
      <dc:creator>mxe2fmk</dc:creator>
      <dc:date>2020-03-23T19:13:33Z</dc:date>
    </item>
  </channel>
</rss>

