Can Palo Alto be used as a reverse proxy?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Can Palo Alto be used as a reverse proxy?

L1 Bithead

We have this scenario that Palo Alto will receive the inbound mail then will be pass to the PMX server(pure message) going to the exchange server. After going to the exchange server, it must be forwarded to the FW but the problem is that the Core Switch doesn't have a default route configured. Is there any way that Palo Alto can receive the mail from the exchange server then send it across the internet? Can Palo Alto be use as reverse proxy?

4 REPLIES 4

L6 Presenter

if you try the Nat suggestions below and it works please update.

In this particular case, why not configure the route towards the PA instead? Or if this isnt possible perhaps settings up a tagged vlan if you dont want to fix (static) routing in your core?

L5 Sessionator

Since the traffic hits inbound first on the PANFW firwall, and we are destination NATing the packets  to the exchange server, configure a source NAT translation on the same NAT rule, and NAT ( IP and port) it to the IP address of the interface through which the exchange server is reachable on. This ensures that the traffic, when it leaves the firewall has the source IP as that of its interface, and destination interface as that of the exchange server. With this setting, the exchange server will respond to the IP address of the firewall, which is known internally in the network ( as a connected route, and for which the switch has a MAC table entry for ). Once this packet reaches the firewall, the firewall will perform the reverse Source and Destination NAT.

Hope this helps.

Best regards,

Karthik 

Have you talking about bidirectional NAT for this particular case, if so I think that is good solution....

Regards,

Predrag

  • 12273 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!