Web server publishing error

Reply
L1 Bithead

Web server publishing error

Hi!

 

Help, please, with an Internal Web server publication.

 

I have a PaloAltor PA-200, PanOS 7.0.19.

 

I have ext. Internet on Eth1/1 (L3-Untrust zone) and LAN on Eth1/2 (L3-Trust zone). In my LAN I have a Server with Web publication (WebServer), which should be accessd from outside (Internet).

 

I`m trying to publish it. But got an error: Mismatch of destination address translation range between original address and translated address

 

Could someone, please, help with fixing th NAT and policy.

 

nat.pngpolicy.png

L7 Applicator

Re: Web server publishing error

Hello,

The destination zone in your screen shot needs to be the same zone that the web server resides in.

 

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/networking/nat/nat-configuration-exa...

 

Hope that helps.

L1 Bithead

Re: Web server publishing error

Thanks for response!

 

Trying to change zone, but got same error. Maybe you could suggest anything else?

 

nat2.png

L7 Applicator

Re: Web server publishing error

Also the destination address should be the IP of the webserver. 

L7 Applicator

Re: Web server publishing error

Sorry menat the translated address. However here is one of my nat rules. Its a bi-directional rules, all that means that incoming traffic and outgoing traffic use the same external IP address.

 

image.png

Just as a personal preference I use NAT rules to just translate and use the security policies to dictate which services are allowed.

L1 Bithead

Re: Web server publishing error

Thanks!

 

Trying to change main NAT, but unsuccessfully. Any ideas?nat3.png

L7 Applicator

Re: Web server publishing error

What IP does your LAN object translate to? It should just be the webservers address.

L1 Bithead

Re: Web server publishing error

LAN - 10.154.10.1/16

WebServer - 10.154.10.7

L7 Applicator

Re: Web server publishing error

Hello,

Put the Webserver address into your NAT rule.

 

image.png

 

Then it should work.

L1 Bithead

Re: Web server publishing error

Hi!

 

Tried to change it, but lost access from LAN to Internet. Same time couldn`t connect the WebServer from outside.

 

Maybe there is another way to do it?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!