Problem with NAT rules

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Problem with NAT rules

L4 Transporter

Hello

Task is simple, give access to 3 IP from Internet to camera on non-standart ports. Ports and  local IP are:

192.168.220.251:554 -> x.x.x.x:554

192.168.220.251:80 -> x.x.x.x:8881

192.168.220.251:8554-8557 -> x.x.x.x:8554-8557

where x.x.x.x is one of IP belongings for my PA and is used for NAT from this zone to untrust.

I created security rules:

2014-05-20_174032.png

and NAT rules:

2014-05-20_174055.png

but it doesn't working. For first step I'd like to test port 80 redirection.

So I try to change something. When I remove 8881tcp from security number 14 I'm able to open web page of IP camera using x.x.x.x:80.

Please tell me where is my mistake?

With regards

SLawek

1 REPLY 1

L5 Sessionator

When creating a Inbound NAT make sure that you source address is the address of where the traffic is coming from. In this case of the camera.

Your destination address is the public interface IP on the palo alto firewall.

Since you have them hidden and not described in the above question not sure if that is what you are doing. Please confirm that.

Following document from page 15 explains different destination NAT scenarios.

Understanding PAN-OS NAT

Please let us know if this helps.


Thank you

Numan

  • 5242 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!