<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2 NAT rules on device in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437430#M97423</link>
    <description>&lt;P&gt;What are you trying to accomplish?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use 2 NAT rules for the same device via schedules. Off work hours, depending on the console I want to use I change the rules for which console gets 1:1 public IP mapping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During work hours when the console is sleeping, or pulling updates, it can sit behind everything.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Sep 2021 16:12:43 GMT</pubDate>
    <dc:creator>LAYER_8</dc:creator>
    <dc:date>2021-09-29T16:12:43Z</dc:date>
    <item>
      <title>2 NAT rules on device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437427#M97422</link>
      <description>&lt;P&gt;Can anyone tell me the pros and cons of having two nat rules for one device?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 16:06:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437427#M97422</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2021-09-29T16:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: 2 NAT rules on device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437430#M97423</link>
      <description>&lt;P&gt;What are you trying to accomplish?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use 2 NAT rules for the same device via schedules. Off work hours, depending on the console I want to use I change the rules for which console gets 1:1 public IP mapping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During work hours when the console is sleeping, or pulling updates, it can sit behind everything.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 16:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437430#M97423</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-09-29T16:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: 2 NAT rules on device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437440#M97425</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160615"&gt;@LAYER_8&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to allow a printer on our network scan to a file server folder on an external network, which is easy I can create a nat rule that allows this with no problem. The issue is that a print server on that same remote server has a nat rule to allow a application from their remote network to print the same printer on our local network.. This all occurs across a IPSec tunnel on the PA and the source and destination are natted IP's. Its a direction issue the scan to network goes from trust to VPN and the print server to internal printer goes the other way VPN to untrust. One printer tow functions only works with two nat rules and it not on schedule this solution needs to be applied to over 50 different printers&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 16:27:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437440#M97425</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2021-09-29T16:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: 2 NAT rules on device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437561#M97437</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can have a device with multiple NAT rules without any issue, but the traffic will match the first matching NAT rulebase entry. In the example that you have given that wouldn't be an issue, and there's really no cons for configuration something like that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 02:43:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437561#M97437</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-09-30T02:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: 2 NAT rules on device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437693#M97448</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if they try to do both the printing from the application and the scan to print at the same time they will both work?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 13:00:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437693#M97448</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2021-09-30T13:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: 2 NAT rules on device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437858#M97461</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okay I went ahead and created the second nat rule and everything seems to be working just fine. The only thing I am considering if there is a benefit to creating a separate security rule since it is already using one that is on the firewall&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 19:20:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437858#M97461</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2021-09-30T19:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: 2 NAT rules on device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437938#M97483</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If it's working under an existing security rule then whether or not you create a separate one for it is really just an administration decision. Personally I like to keep my rulebase as detailed as possible so I know exactly what the rule is supposed to be allowing, but I know others prefer to keep a cleaner rulebase that isn't as detailed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 01:56:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/437938#M97483</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-10-01T01:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: 2 NAT rules on device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/438428#M97536</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;So what is your opinion about using a bidirectional nat on the application to print rule to allow access for the scan to the file folder which I guess I would have to add the file server too. I don't like it but my boss asked me to look at it so their aren't so many rules that need to be added&lt;/P&gt;&lt;P&gt;What are the pros and cons of using a bidirectional nat and combining these two rules, won't it keep the the application to printer&amp;nbsp; when the scan to network folder is being used?&amp;nbsp; Is a bidirectional nat rule less secure?&amp;nbsp; The scan to network would then have access to servers it doesn't even scan too as well as the app to printer would have access to a file server it never uses. Anyway looking for the best way to do these two function both in security, number or rules needed.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 19:38:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/438428#M97536</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2021-10-04T19:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: 2 NAT rules on device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/438660#M99452</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'd be hesitant to really give an opinion on that without knowing more about how the NAT entry is actually configured. Keeping in mind that bi-directional NATs effectively create the same NAT statement in reverse from the firewalls aspect, that checkbox can create security issues if not properly configured.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 02:05:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-nat-rules-on-device/m-p/438660#M99452</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-10-05T02:05:59Z</dc:date>
    </item>
  </channel>
</rss>

