<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT rules for Email exchange/Email Gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-for-email-exchange-email-gateway/m-p/330715#M83818</link>
    <description>&lt;P&gt;Ok, so after lot of checking.&lt;/P&gt;&lt;P&gt;turned out to be ARP on the Router was keeping the exchange IP address with the old Firewall MAC address which caused the traffic from the exchange to be dropped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all I had to do is to change ARP age out time to 30 seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all is good and the rules were correct.&lt;/P&gt;</description>
    <pubDate>Sun, 31 May 2020 10:48:01 GMT</pubDate>
    <dc:creator>Samerrafidsaleem</dc:creator>
    <dc:date>2020-05-31T10:48:01Z</dc:date>
    <item>
      <title>NAT rules for Email exchange/Email Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-for-email-exchange-email-gateway/m-p/329600#M83658</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two IP addresses used for inbound/outbound emails on our email gateway.&lt;/P&gt;&lt;P&gt;I have created the attached rules NAT and Security and I wanted to get opinions if its correct because I tested it and it seems something wrong that prevent emails from in/outbounding and even the web mail access did not work...your advice please.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT Rules.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25810i046921754A50410E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT Rules.JPG" alt="NAT Rules.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Security policy.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25809i4F6C1EAB072029EB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Security policy.JPG" alt="Security policy.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 May 2020 10:02:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-for-email-exchange-email-gateway/m-p/329600#M83658</guid>
      <dc:creator>Samerrafidsaleem</dc:creator>
      <dc:date>2020-05-23T10:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rules for Email exchange/Email Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-for-email-exchange-email-gateway/m-p/329644#M83667</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm sure there is a reason you have two external IP's for this? But it can be accomplished with one. Check out this article on NAT.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllzCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllzCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;</description>
      <pubDate>Sat, 23 May 2020 16:51:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-for-email-exchange-email-gateway/m-p/329644#M83667</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-05-23T16:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rules for Email exchange/Email Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-for-email-exchange-email-gateway/m-p/329646#M83668</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have one external IP, but two private ip addresses for the email gateway&amp;nbsp;&lt;/P&gt;&lt;P&gt;first ip for outbound 172.16.16.22&lt;/P&gt;&lt;P&gt;second for inbound 172.16.16.23&lt;/P&gt;&lt;P&gt;these in dmz&lt;/P&gt;&lt;P&gt;and for web mail access for the exchange I have 10.211.0.30 which is on the inside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 May 2020 18:01:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-for-email-exchange-email-gateway/m-p/329646#M83668</guid>
      <dc:creator>Samerrafidsaleem</dc:creator>
      <dc:date>2020-05-23T18:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rules for Email exchange/Email Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-for-email-exchange-email-gateway/m-p/330715#M83818</link>
      <description>&lt;P&gt;Ok, so after lot of checking.&lt;/P&gt;&lt;P&gt;turned out to be ARP on the Router was keeping the exchange IP address with the old Firewall MAC address which caused the traffic from the exchange to be dropped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all I had to do is to change ARP age out time to 30 seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all is good and the rules were correct.&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 10:48:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-rules-for-email-exchange-email-gateway/m-p/330715#M83818</guid>
      <dc:creator>Samerrafidsaleem</dc:creator>
      <dc:date>2020-05-31T10:48:01Z</dc:date>
    </item>
  </channel>
</rss>

