<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: nat64 error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat64-error/m-p/319101#M81869</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I am struggling with the destination NAT here.&lt;/P&gt;&lt;P&gt;I have a challenge where I want the IPv6 initiated host (any - internet) to be NATTED so that it can reach Private IP address port 443.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/networking/nat64/configure-nat64/ipv6-initiated-communication.html#iddb41c324-5690-4ca3-b54a-6ec24ed3f57d" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/networking/nat64/configure-nat64/ipv6-initiated-communication.html#iddb41c324-5690-4ca3-b54a-6ec24ed3f57d&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Article clearly says, IPv6 initiated traffic.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[...] Configure the destination IPv6 address as either the Well-Known Prefix or the NSP that the DNS64 server uses. (You do not configure the full IPv6 destination address in the rule.)[...]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I mean, what ? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I already have IPv6 on external interface on the firewall that can be reached from IPv6 network&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I merely want not traffic that arrives at that interface on specific port to be NATTED behind some ipv4 address I can create and be forwarded to local IP address on the LAN, that seems to be impossible to do.&lt;BR /&gt;his is extracted from the destination IPv6 address"&amp;nbsp;&lt;BR /&gt;How does the IPv4 of LAN suppose to be extracted from the destination IPv6 address where IPv6 address is of something entirely different( here its Palo Alto external internet facing firewall)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Mar 2020 20:05:57 GMT</pubDate>
    <dc:creator>PiankaMariusz</dc:creator>
    <dc:date>2020-03-27T20:05:57Z</dc:date>
    <item>
      <title>nat64 error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat64-error/m-p/67615#M39618</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to do a NAT from ipv6 to ipv4.&lt;/P&gt;
&lt;P&gt;On commit I have an error&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"Nat64 needs an ipv4 in the rule for dest xlat"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rule : from untrust to untrust , destination ip is ipv6 and translated address is ipv4 destination NAT&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 20:54:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat64-error/m-p/67615#M39618</guid>
      <dc:creator>PanIst</dc:creator>
      <dc:date>2015-11-03T20:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: nat64 error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat64-error/m-p/67647#M39622</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't need IPv4 destination NAT for this scenario (IPv6 to IPv4) :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source IP : Any IPv6 address&lt;/P&gt;
&lt;P&gt;Destination IP : NAT64 IPv6 prefix with RFC 6052 compliant netmask&lt;/P&gt;
&lt;P&gt;Source translation : Dynamic IP and port mode using IPv4 address&lt;/P&gt;
&lt;P&gt;Destination translation : None (this is extracted from the destination IPv6 address)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note that this implementation requires&amp;nbsp;a DNS64 server that the IPv6 client can communicate with to synthesize AAAA records from A records. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a look also at the following document that has a configuration example on how to NAT64 IPv6 to IPv4 :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-NAT64-on-Palo-Alto-Firewalls-IPv6-to-IPv4/ta-p/60249" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-NAT64-on-Palo-Alto-Firewalls-IPv6-to-IPv4/ta-p/60249&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 09:57:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat64-error/m-p/67647#M39622</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2015-11-04T09:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: nat64 error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat64-error/m-p/319101#M81869</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I am struggling with the destination NAT here.&lt;/P&gt;&lt;P&gt;I have a challenge where I want the IPv6 initiated host (any - internet) to be NATTED so that it can reach Private IP address port 443.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/networking/nat64/configure-nat64/ipv6-initiated-communication.html#iddb41c324-5690-4ca3-b54a-6ec24ed3f57d" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/networking/nat64/configure-nat64/ipv6-initiated-communication.html#iddb41c324-5690-4ca3-b54a-6ec24ed3f57d&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Article clearly says, IPv6 initiated traffic.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[...] Configure the destination IPv6 address as either the Well-Known Prefix or the NSP that the DNS64 server uses. (You do not configure the full IPv6 destination address in the rule.)[...]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I mean, what ? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I already have IPv6 on external interface on the firewall that can be reached from IPv6 network&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I merely want not traffic that arrives at that interface on specific port to be NATTED behind some ipv4 address I can create and be forwarded to local IP address on the LAN, that seems to be impossible to do.&lt;BR /&gt;his is extracted from the destination IPv6 address"&amp;nbsp;&lt;BR /&gt;How does the IPv4 of LAN suppose to be extracted from the destination IPv6 address where IPv6 address is of something entirely different( here its Palo Alto external internet facing firewall)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 20:05:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat64-error/m-p/319101#M81869</guid>
      <dc:creator>PiankaMariusz</dc:creator>
      <dc:date>2020-03-27T20:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: nat64 error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat64-error/m-p/397070#M91446</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100793"&gt;@PiankaMariusz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How did you achieve your configuration then?&lt;/P&gt;&lt;P&gt;I also have the same exact requirement,can you please help..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance mate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Apr 2021 13:52:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat64-error/m-p/397070#M91446</guid>
      <dc:creator>shubhamG</dc:creator>
      <dc:date>2021-04-10T13:52:16Z</dc:date>
    </item>
  </channel>
</rss>

