<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does NAT64 works for inbound NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/does-nat64-works-for-inbound-nat/m-p/437050#M97388</link>
    <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183271"&gt;@Deepak25&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, this is correct. You will need GUA IPv6 (Public IPv6) and in this case you do not have to configure NAT64.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A. Yes, you can enabled IPv6 on existing interface. The configuration is fairly straightforward. Below is a sample from one of the implementation:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_1-1632778348847.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36659iEBD022DF700DBF64/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_1-1632778348847.png" alt="PavelK_1-1632778348847.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_2-1632778435973.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36660iE5441DFC26DEC3E8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_2-1632778435973.png" alt="PavelK_2-1632778435973.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;B. Yes, this is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For 6to4 tunnel, I found this article:&amp;nbsp;&lt;A href="https://weberblog.net/ipv6-through-ipv4-vpn-tunnel-with-palo-alto/" target="_blank"&gt;https://weberblog.net/ipv6-through-ipv4-vpn-tunnel-with-palo-alto/&lt;/A&gt;&amp;nbsp;however I think GRE tunnel with IPv6 would be better solution:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/gre-tunnels/create-a-gre-tunnel.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/gre-tunnels/create-a-gre-tunnel.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Mon, 27 Sep 2021 22:22:06 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2021-09-27T22:22:06Z</dc:date>
    <item>
      <title>Does NAT64 works for inbound NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-nat64-works-for-inbound-nat/m-p/436189#M96239</link>
      <description>&lt;P&gt;Currently we have configured inbound NAT for DMZ application which is on ipv4. Public ip used for it is&amp;nbsp; ipv4.&lt;/P&gt;&lt;P&gt;Due to some requirement client from outside network will be coming from ipv6 public ip to access the application. In this case our nat is not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have found NAT64 feature in below doc , but given example is for outbound NAT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIFCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIFCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTuCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTuCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat64/ipv6-initiated-communication.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat64/ipv6-initiated-communication.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does NAT64 support for inbound NAT. How we can achieve by keeping actual server private IP on IPv4 ?&lt;/P&gt;&lt;P&gt;If we use DNS64 , let's say firewall translate the destination ipv6 ip into public ipv4 ip. Do we need private ip of server in destination&amp;nbsp;&lt;/P&gt;&lt;P&gt;translation ?&lt;/P&gt;&lt;P&gt;How firewall will translate DNS64 ipv6 public ip to ipv4 public ip ?&lt;/P&gt;&lt;P&gt;Do we need to assign public ipv6 ip on outside interface of firewall ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any other solution to achieve our requirement ?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 16:33:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-nat64-works-for-inbound-nat/m-p/436189#M96239</guid>
      <dc:creator>Deepak25</dc:creator>
      <dc:date>2021-09-23T16:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Does NAT64 works for inbound NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-nat64-works-for-inbound-nat/m-p/436617#M96286</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183271"&gt;@Deepak25&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The intended use of NAT64 / DNS64 is to allow internal IPv6 only clients to communicate with IPv4 targets on Internet. The links you mentioned are detailing on how this works. The DNS64 is performed on 3rd party system, not on Palo Alto Firewall. Only NAT64 is performed by Firewall itself. Since your requirement is to allow IPv6 traffic from Untrust (Outside) interface to single IPv4 server on Trust (Inside), the NAT64 is not suitable solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setting up static IPv6 to IPv4 NAT from Untrust to Trust, for example /128 address to /32 is not possible. Palo Alto Firewall expects smallest prefix to be /96 otherwise the commit will fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Probably the easiest way to achieve your requirement is to enable IPv6 on your Untrust interface, then configure one interface for DMZ and enable it for IPv6 as well. In this DMZ built a server that will do Reverse Proxy IPv6 to IPv4. You can do it with open source, for example NGINX or luxury way with commercial load balancers such as F5 LTM or Citrix NetScaler. In this case you can preserve server and rest of the infrastructure with IPv4 only and let Reverse Proxy expose server from outside by IPv6.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An alternative, would be to enable dual stack on Palo Alto Firewall and all intermediate nodes and bring IPv6 directly to server. If this is not possible, then alternative would be build 6to4 tunnel to hop over internal IPv4 infrastructure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Sep 2021 07:03:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-nat64-works-for-inbound-nat/m-p/436617#M96286</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-26T07:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Does NAT64 works for inbound NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-nat64-works-for-inbound-nat/m-p/436802#M96303</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So to achieve our requirement public ipv6 ip is needed and NAT64 nat do not require. Is it correct ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we are using reverse proxy for ipv6 to ipv4 ,&lt;/P&gt;&lt;P&gt;A. can we enable ipv6 on same DMZ interface?&lt;/P&gt;&lt;P&gt;B. ipv6 ip of proxy server will be as a destination nat private ip ..right ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How we can configure 6to4 tunnel in palo alto ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 09:34:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-nat64-works-for-inbound-nat/m-p/436802#M96303</guid>
      <dc:creator>Deepak25</dc:creator>
      <dc:date>2021-09-27T09:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Does NAT64 works for inbound NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-nat64-works-for-inbound-nat/m-p/437050#M97388</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183271"&gt;@Deepak25&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, this is correct. You will need GUA IPv6 (Public IPv6) and in this case you do not have to configure NAT64.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A. Yes, you can enabled IPv6 on existing interface. The configuration is fairly straightforward. Below is a sample from one of the implementation:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_1-1632778348847.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36659iEBD022DF700DBF64/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_1-1632778348847.png" alt="PavelK_1-1632778348847.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_2-1632778435973.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36660iE5441DFC26DEC3E8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_2-1632778435973.png" alt="PavelK_2-1632778435973.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;B. Yes, this is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For 6to4 tunnel, I found this article:&amp;nbsp;&lt;A href="https://weberblog.net/ipv6-through-ipv4-vpn-tunnel-with-palo-alto/" target="_blank"&gt;https://weberblog.net/ipv6-through-ipv4-vpn-tunnel-with-palo-alto/&lt;/A&gt;&amp;nbsp;however I think GRE tunnel with IPv6 would be better solution:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/gre-tunnels/create-a-gre-tunnel.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/gre-tunnels/create-a-gre-tunnel.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 22:22:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-nat64-works-for-inbound-nat/m-p/437050#M97388</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-27T22:22:06Z</dc:date>
    </item>
  </channel>
</rss>

