<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT RULE - IPsec VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/324176#M82773</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, it will be bidirectional.&lt;/P&gt;&lt;P&gt;I agree with you when you said that 1.1.1.1 shouldn't be in the&amp;nbsp; VPN. Since that is what paloalto would do if I select bidirectional source NAT,&lt;/P&gt;&lt;P&gt;that is why I think I may have to use 2 unidirectional rules.&lt;/P&gt;&lt;P&gt;I do not quite understand when you said that: "&lt;SPAN&gt;IP 1.1.1.1 would be consider to be part of internal as it is going to DNAT with internal IP 192.168.1.1"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you mean, when creating the reverse rule, instead of &lt;STRONG&gt;external&lt;/STRONG&gt; I should put &lt;STRONG&gt;Internal&lt;/STRONG&gt; as&amp;nbsp; dest zone??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Apr 2020 02:48:18 GMT</pubDate>
    <dc:creator>joseglez</dc:creator>
    <dc:date>2020-04-22T02:48:18Z</dc:date>
    <item>
      <title>NAT RULE - IPsec VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/323961#M82747</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I am implementing an IPsec VPN and I have to NAT the source IP address, but I am very confused with the bidirectional source NAT,&lt;/P&gt;&lt;P&gt;Lets say my local IP=192.168.1.1 (natted to 1.1.1.1), remote IP in the other side of the VPN= 10.10.10.1&lt;/P&gt;&lt;P&gt;For example If I configure:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Src Zone&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Src IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dest Zone&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dest. IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NAT&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Internal&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.1.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VPN&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10.10.10.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; source nat: 1.1.1.1&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;(bidirectional)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;behind the scene the&amp;nbsp;&lt;EM&gt;returning&lt;/EM&gt; NAT rule created will be:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Src Zone&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Src IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dest Zone&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dest. IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NAT&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Any&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Any&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;VPN&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dest. nat: 192.168.1.1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My confusion is based in the fact that &lt;STRONG&gt;1.1.1.1 is not in the VPN zone&lt;/STRONG&gt;, its a external IP in the External zone so I think I cannot use bidirectional NAT&amp;nbsp;in this scenario and I have to create 2 rules for each direction like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Src Zone&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Src IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dest Zone&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dest. IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NAT&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Internal&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.1.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VPN&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10.10.10.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; source nat: 1.1.1.1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Src Zone&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Src IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dest Zone&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dest. IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NAT&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;VPN&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10.10.10.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;External&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dest. nat: 192.168.1.1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I wrong about this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 03:26:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/323961#M82747</guid>
      <dc:creator>joseglez</dc:creator>
      <dc:date>2020-04-21T03:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: NAT RULE - IPsec VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/323984#M82750</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138833"&gt;@joseglez&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all, is it bidirectional tunnel (both sides will be initiator and responder) then only you need BI-Directional NAT ?&lt;/P&gt;&lt;P&gt;If only any of the side is initiator and other responder, then you don't need Bi-Directional NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now you want to NAT IP 192.168.1.1 with 1.1.1.1, in this case,&lt;/P&gt;&lt;P&gt;1. IP 1.1.1.1 shouldn't be part of VPN ZONE. Destination IP addresses will be part of VPN zone (i.e. 10.10.10.1 ). Just make sure you have route towards desired tunnel interface for this IP/network.&lt;/P&gt;&lt;P&gt;2. Configure proper NAT Rule. So IP 1.1.1.1 would be consider to be part of internal as it is going to DNAT with internal IP 192.168.1.1&lt;/P&gt;&lt;P&gt;3. Also make sure NAT IP 1.1.1.1 is part of proxy ID configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps you!&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 07:10:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/323984#M82750</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-04-21T07:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: NAT RULE - IPsec VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/324176#M82773</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, it will be bidirectional.&lt;/P&gt;&lt;P&gt;I agree with you when you said that 1.1.1.1 shouldn't be in the&amp;nbsp; VPN. Since that is what paloalto would do if I select bidirectional source NAT,&lt;/P&gt;&lt;P&gt;that is why I think I may have to use 2 unidirectional rules.&lt;/P&gt;&lt;P&gt;I do not quite understand when you said that: "&lt;SPAN&gt;IP 1.1.1.1 would be consider to be part of internal as it is going to DNAT with internal IP 192.168.1.1"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you mean, when creating the reverse rule, instead of &lt;STRONG&gt;external&lt;/STRONG&gt; I should put &lt;STRONG&gt;Internal&lt;/STRONG&gt; as&amp;nbsp; dest zone??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 02:48:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/324176#M82773</guid>
      <dc:creator>joseglez</dc:creator>
      <dc:date>2020-04-22T02:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAT RULE - IPsec VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/324191#M82777</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138833"&gt;@joseglez&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, for reverse rule (inbound traffic), you need to put destination zone as internal &lt;STRONG&gt;not external. &lt;/STRONG&gt;Then only traffic will be forwarded to internal IP 192.168.1.1. Normally while hosting internal server also, we configure policies in same way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your NAT would be like -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Bi-Directional NAT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SZONE - Internal&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;S-IP - 192.168.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DZONE - VPN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;D-IP - 10.10.10.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;S-NAT-IP - 1.1.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security Policy for outbound traffic -&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SZONE - Internal&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;S-IP - 192.168.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DZONE - VPN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;D-IP - 10.10.10.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security Policy for inbound traffic -&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SZONE - VPN&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;S-IP - 10.10.10.1&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DZONE - Internal&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;D-IP - 1.1.1.1&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Also configure proper routes and proxy-id configuration. With this, everything should work as expected. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 06:39:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/324191#M82777</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-04-22T06:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAT RULE - IPsec VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/324280#M82799</link>
      <description>&lt;P&gt;Great, thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I included the after NAT IPs in the proxy IDs also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 14:20:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rule-ipsec-vpn/m-p/324280#M82799</guid>
      <dc:creator>joseglez</dc:creator>
      <dc:date>2020-04-22T14:20:40Z</dc:date>
    </item>
  </channel>
</rss>

