<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic U-NAT Double NAT - DNAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/u-nat-double-nat-dnat/m-p/426927#M94556</link>
    <description>&lt;P&gt;Good morning, first of all thank you very much for your support.&lt;/P&gt;&lt;P&gt;I have the following case scenario:&lt;/P&gt;&lt;P&gt;FQDN: Dyndns ( paloalto01xxxalias.dynalias.net )&lt;BR /&gt;Modem/router/ADSL dynamic IP Public&lt;BR /&gt;Modem/router/ADSL LAN IP 192.160.1.254&lt;BR /&gt;Modem/router/ADSL NAT1-1 to Palo Alto Wan External Interface&lt;BR /&gt;Palo Alto Wan Interface 192.168.1.74 Gateway: 192.168.1.254&lt;/P&gt;&lt;P&gt;Palo Alto Dnat 192.168.1.74 port 9000 to LAN ( Palo Alto Lan ) 192.100.11.90 Port 9000.&lt;/P&gt;&lt;P&gt;Palo Alto Dnat 192.168.1.74 port 8000 to LAN ( Palo Alto Lan ) 192.100.11.90 Port 8000.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet----FQDN-Dyndns-----WAN:dynamic IP Public-Modem/router/ADSL---NAT:1:1----WAN Palo Alto Palo Alto----LAN Palo ALto----- 192.100.11.90 and 192.100.11.80 ( LAN Servers ).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNAT details:&lt;BR /&gt;-DNAT External zone ---- 192.168.1.74 ---- LAN zone ---- IP 192.100.11.90.&lt;BR /&gt;Services: TCP_9000 ( TCP:9000 )---Operates OK from outside.&lt;/P&gt;&lt;P&gt;-DNAT External zone ---- 192.168.1.74 ---- LAN zone ---- IP 192.100.11.80&lt;BR /&gt;Services: TCP_8000 ( TCP:8000 )---Operates OK from outside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I perform the DNAT, from the outside it operates correctly OK. Since the connections when arriving and entering to the modem, pointing to the FQDN of dyndns, when arriving to the Modem/Router are nated to the Palo Alto to its WAN interface, the high stick then applies the DNAT ( detailed above ) and forwards it to the IP 192.100.11.90:9000 and 192.100.11.80:8000 this OK, correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem occurs when, from the local network 192.100.11.0/24 and the other two networks 192.100.13.0/24 and 192.100.14.0/24, you try to go to the FQDN paloalto01xxxalias.dynalias.net the DNAT is not applied.&lt;/P&gt;&lt;P&gt;Try to perform a U-NAT as I have applied in other cases, from other firewalls.&lt;BR /&gt;In this case I have a DOUBLE NAT, the equipment MODEM/Router ( Nat:1:1 ) and the firewall Palo Alto, therefore if I try to apply the UNAT, in theory it is like that:&lt;/P&gt;&lt;P&gt;Source: LAN Network, LAN2 Network, LAN3 Network&lt;BR /&gt;Destination: External WAN: 192.168.1.74 ( IP wan of the Palo Alto )&lt;BR /&gt;Service: TCP:8000 port&lt;BR /&gt;Then 192.100.11.80 ( LAN IP ) Port 8000. This does not work because I must and need to reach the FQDN paloalto01xxxalias.dynalias.net, not the WAN IP of Palo Alto, and from there the NAT must go down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try to perform another U-NAT, as follows:&lt;/P&gt;&lt;P&gt;First create an address object as FQDN: paloalto01xxxalias.dynalias.net.&lt;/P&gt;&lt;P&gt;Generate the Dnat rule as follows:&lt;/P&gt;&lt;P&gt;Source: LAN Network, LAN2 Network, LAN3 Network&lt;BR /&gt;Destination: External WAN Destination Address FQDN: paloalto01xxxalias.dynalias.net&lt;BR /&gt;Service: TCP:8000 port&lt;BR /&gt;Destination Translate ( 192.168.1.74) 8000 tcp Port&lt;/P&gt;&lt;P&gt;And this didn't work either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please your help and support, to see how I can do that from the LAN networks to reach the FQDN paloalto01xxxalias.dynalias.net and that the DNAT is applied correctly.&lt;BR /&gt;From external networks and from the outside, if it works correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much, I remain attentive, best regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 15 Aug 2021 23:31:36 GMT</pubDate>
    <dc:creator>Metgatz</dc:creator>
    <dc:date>2021-08-15T23:31:36Z</dc:date>
    <item>
      <title>U-NAT Double NAT - DNAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/u-nat-double-nat-dnat/m-p/426927#M94556</link>
      <description>&lt;P&gt;Good morning, first of all thank you very much for your support.&lt;/P&gt;&lt;P&gt;I have the following case scenario:&lt;/P&gt;&lt;P&gt;FQDN: Dyndns ( paloalto01xxxalias.dynalias.net )&lt;BR /&gt;Modem/router/ADSL dynamic IP Public&lt;BR /&gt;Modem/router/ADSL LAN IP 192.160.1.254&lt;BR /&gt;Modem/router/ADSL NAT1-1 to Palo Alto Wan External Interface&lt;BR /&gt;Palo Alto Wan Interface 192.168.1.74 Gateway: 192.168.1.254&lt;/P&gt;&lt;P&gt;Palo Alto Dnat 192.168.1.74 port 9000 to LAN ( Palo Alto Lan ) 192.100.11.90 Port 9000.&lt;/P&gt;&lt;P&gt;Palo Alto Dnat 192.168.1.74 port 8000 to LAN ( Palo Alto Lan ) 192.100.11.90 Port 8000.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet----FQDN-Dyndns-----WAN:dynamic IP Public-Modem/router/ADSL---NAT:1:1----WAN Palo Alto Palo Alto----LAN Palo ALto----- 192.100.11.90 and 192.100.11.80 ( LAN Servers ).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNAT details:&lt;BR /&gt;-DNAT External zone ---- 192.168.1.74 ---- LAN zone ---- IP 192.100.11.90.&lt;BR /&gt;Services: TCP_9000 ( TCP:9000 )---Operates OK from outside.&lt;/P&gt;&lt;P&gt;-DNAT External zone ---- 192.168.1.74 ---- LAN zone ---- IP 192.100.11.80&lt;BR /&gt;Services: TCP_8000 ( TCP:8000 )---Operates OK from outside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I perform the DNAT, from the outside it operates correctly OK. Since the connections when arriving and entering to the modem, pointing to the FQDN of dyndns, when arriving to the Modem/Router are nated to the Palo Alto to its WAN interface, the high stick then applies the DNAT ( detailed above ) and forwards it to the IP 192.100.11.90:9000 and 192.100.11.80:8000 this OK, correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem occurs when, from the local network 192.100.11.0/24 and the other two networks 192.100.13.0/24 and 192.100.14.0/24, you try to go to the FQDN paloalto01xxxalias.dynalias.net the DNAT is not applied.&lt;/P&gt;&lt;P&gt;Try to perform a U-NAT as I have applied in other cases, from other firewalls.&lt;BR /&gt;In this case I have a DOUBLE NAT, the equipment MODEM/Router ( Nat:1:1 ) and the firewall Palo Alto, therefore if I try to apply the UNAT, in theory it is like that:&lt;/P&gt;&lt;P&gt;Source: LAN Network, LAN2 Network, LAN3 Network&lt;BR /&gt;Destination: External WAN: 192.168.1.74 ( IP wan of the Palo Alto )&lt;BR /&gt;Service: TCP:8000 port&lt;BR /&gt;Then 192.100.11.80 ( LAN IP ) Port 8000. This does not work because I must and need to reach the FQDN paloalto01xxxalias.dynalias.net, not the WAN IP of Palo Alto, and from there the NAT must go down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try to perform another U-NAT, as follows:&lt;/P&gt;&lt;P&gt;First create an address object as FQDN: paloalto01xxxalias.dynalias.net.&lt;/P&gt;&lt;P&gt;Generate the Dnat rule as follows:&lt;/P&gt;&lt;P&gt;Source: LAN Network, LAN2 Network, LAN3 Network&lt;BR /&gt;Destination: External WAN Destination Address FQDN: paloalto01xxxalias.dynalias.net&lt;BR /&gt;Service: TCP:8000 port&lt;BR /&gt;Destination Translate ( 192.168.1.74) 8000 tcp Port&lt;/P&gt;&lt;P&gt;And this didn't work either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please your help and support, to see how I can do that from the LAN networks to reach the FQDN paloalto01xxxalias.dynalias.net and that the DNAT is applied correctly.&lt;BR /&gt;From external networks and from the outside, if it works correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much, I remain attentive, best regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Aug 2021 23:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/u-nat-double-nat-dnat/m-p/426927#M94556</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2021-08-15T23:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: U-NAT Double NAT - DNAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/u-nat-double-nat-dnat/m-p/426968#M94563</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can verify below KB article which gives all the steps to allow such traffic flow.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEiCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEiCAK&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 06:23:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/u-nat-double-nat-dnat/m-p/426968#M94563</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-08-16T06:23:09Z</dc:date>
    </item>
  </channel>
</rss>

