How to configure dynamic NAT IPs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How to configure dynamic NAT IPs

L3 Networker

I have a german ADSL connection and would like to make it accessible from outside. My server has internally the IP 10.0.109.111. From outside it is accessible via a DynDNS name because the public IP changes daily.
My router has the 192.168.4.1 IP and the PA 200 on the eth3 has the IP 192.168.4.2. From within the Internet I can also access this IP.
How do I set NAT policies to get from external to internal?

Look my policies...

2018-06-07 16_25_52-PA220-MZH-BW.jpg2018-06-07 16_25_41-PA220-MZH-BW.jpg2018-06-07 16_25_23-PA220-MZH-BW.jpg2018-06-07 16_24_59-PA220-MZH-BW.jpg

3 REPLIES 3

Cyber Elite
Cyber Elite

I understand that this dynamic public IP is assigned to wan interface of the router. In this case you first need to set up port forwarning on router and then on Palo.

In this case Palo NAT rule looks like this.

 

Original Packet tab
Source zone - l3-untrust-1u1
Destination zone - l3-untrust-1u1
Destination interface - any will do the trick
Destination Address - 192.168.4.2

 

Translated Packet tab
Translation Type - Static IP
Translated Address - 10.0.109.111

 

Security policy
Source zone - l3-untrust-1u1
Destination zone - l3-trust
Source IP - any
Destination IP - 192.168.4.2

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hello,

In addition to this I would recommned not using clear text protocols such as FTP. There are free SFTP servers out there that you can use and would make your systems more secure.

 

Regards,

@Raido_Rattameisterthaht it was.. Destination interface - any will do the trick

 

@OtakarKlierI know ftp is bad.. but i think its an easy way to test connections. So i have a test server and can connect from outside to this one.

  • 2025 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!