<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Special NAT configuration. Asking about possibility in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389316#M90616</link>
    <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92212"&gt;@jeremylo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why don't you apply a source NAT on Spoke 2 (hiding all requests to 172.16.200.62 behind the firewall interface 172.16.200.x)?&lt;/P&gt;</description>
    <pubDate>Fri, 05 Mar 2021 08:42:23 GMT</pubDate>
    <dc:creator>JoergSchuetter</dc:creator>
    <dc:date>2021-03-05T08:42:23Z</dc:date>
    <item>
      <title>Special NAT configuration. Asking about possibility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389297#M90615</link>
      <description>&lt;P&gt;I have a working Hub &amp;amp; Spoke VPN network. Computers in Spoke1 can reach the computers in Spoke2 and vice versa.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some reason, a particular device in Spoke2 with IP 172.16.200.62 can only be reached by the computers in the same subnet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to know is it possible to assign a 172.16.200.x IP address to the computers in Spoke1 when they attempt to connect to that special device. I'm not sure this will achieve my target or not, but at least I can learn a new NAT technique if such configuration does exist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 3 firewalls below are PA-820.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HubAndSpoke.jpg" style="width: 697px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30197i33D50493100B6F2B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="HubAndSpoke.jpg" alt="HubAndSpoke.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 08:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389297#M90615</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2021-03-05T08:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Special NAT configuration. Asking about possibility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389316#M90616</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92212"&gt;@jeremylo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why don't you apply a source NAT on Spoke 2 (hiding all requests to 172.16.200.62 behind the firewall interface 172.16.200.x)?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 08:42:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389316#M90616</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2021-03-05T08:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Special NAT configuration. Asking about possibility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389462#M90626</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Simple fix for this is by creating a NAT rule&lt;/P&gt;&lt;P&gt;Nat from Spoke1 to Spoke2 -&lt;/P&gt;&lt;P&gt;Source Zone - Tunnel Interface Spoke1&lt;/P&gt;&lt;P&gt;Source IP Address - 192.168.100.0/24&lt;/P&gt;&lt;P&gt;Destination Zone&amp;nbsp; - Tunnel Interface Spoke2&lt;/P&gt;&lt;P&gt;Destination Address - 172.16.200.0/24&lt;/P&gt;&lt;P&gt;Source Translation - Dynamic IP and Port&lt;/P&gt;&lt;P&gt;Translated IP - 172.16.200.100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this will help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 19:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389462#M90626</guid>
      <dc:creator>Pawel_G</dc:creator>
      <dc:date>2021-03-05T19:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Special NAT configuration. Asking about possibility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389637#M90634</link>
      <description>&lt;P&gt;Bingo! It works!&lt;/P&gt;&lt;P&gt;Thanks Pawel.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 02:00:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389637#M90634</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2021-03-08T02:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Special NAT configuration. Asking about possibility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389639#M90635</link>
      <description>&lt;P&gt;Hello Joerg,&lt;/P&gt;&lt;P&gt;This is a solution too. However, I also want to keep track of which computer in Spoke1 have connected to Spoke2.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 01:59:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/special-nat-configuration-asking-about-possibility/m-p/389639#M90635</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2021-03-08T01:59:28Z</dc:date>
    </item>
  </channel>
</rss>

