<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Passing original IP information for source NAT translated traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/passing-original-ip-information-for-source-nat-translated/m-p/335199#M84492</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42079"&gt;@DelvinC&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't think of a built-in feature that will do this for you.&lt;/P&gt;
&lt;P&gt;First thing that came to mind was to use x-forward-for but that's a different scenario/setup than yours and can't be used for this I'm afraid.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other users might have ideas or scripts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good luck !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 25 Jun 2020 07:11:35 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2020-06-25T07:11:35Z</dc:date>
    <item>
      <title>Passing original IP information for source NAT translated traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passing-original-ip-information-for-source-nat-translated/m-p/334891#M84443</link>
      <description>&lt;P&gt;I don't know the feasibility of this on the PAN. I've seen this done by means of custom scripts on load balancers. But, I thought it might be better to ask here since there are always more than one person with the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The current situation:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have a PAN firewall between the Internet and my HA-Proxy server.&lt;/LI&gt;&lt;LI&gt;The source traffic arrives at the ingress of my PAN firewall from the Internet.&lt;/LI&gt;&lt;LI&gt;The traffic is forwarded to the destination HA proxy server by means of a destination translation NAT rule that also enforces a source NAT.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;The source NAT translates the original source IP to the interface IP of the firewall.&lt;/LI&gt;&lt;LI&gt;Given the uniqueness of the environment, we can not get rid of the source NAT.&lt;/LI&gt;&lt;LI&gt;The HA-proxy server has a separate direct Internet access for outbound connectivity that doesn't go through the PAN firewall. However, the inbound connections from the Internet are source NAT'd through the PAN firewall.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;My current requirement:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The HA-Proxy should be able to correlate or have knowledge about the original source IP address.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So, anyone out there who has run into a similar scenario before? Any hacks?&lt;BR /&gt;Lets brainstorm this out!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 00:25:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passing-original-ip-information-for-source-nat-translated/m-p/334891#M84443</guid>
      <dc:creator>DelvinC</dc:creator>
      <dc:date>2020-06-24T00:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Passing original IP information for source NAT translated traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passing-original-ip-information-for-source-nat-translated/m-p/335199#M84492</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42079"&gt;@DelvinC&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't think of a built-in feature that will do this for you.&lt;/P&gt;
&lt;P&gt;First thing that came to mind was to use x-forward-for but that's a different scenario/setup than yours and can't be used for this I'm afraid.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other users might have ideas or scripts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good luck !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 25 Jun 2020 07:11:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passing-original-ip-information-for-source-nat-translated/m-p/335199#M84492</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-06-25T07:11:35Z</dc:date>
    </item>
  </channel>
</rss>

