Can't create Nat rule using more than one source address

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Can't create Nat rule using more than one source address

L3 Networker

Hi all,

 

I'm trying to create Nat rule for source translate when the source is address group and it will not be bi-directional.

 

The address group include 2 address from objects.

The source translate is Static-IP tried to put object and specifric IP address with subnet (/32)

 

I keep receiving the following error, also tried to use two-source address instead of address group with success.

 

I'm on PANOS 8.1.1

 

Nat rule error.jpg

1 accepted solution

Accepted Solutions

In this case you can't use static-ip.

Choose "Dynamic IP And Port" from droppdown.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

6 REPLIES 6

Cyber Elite
Cyber Elite

If you have  more than 1 IPs on one side then  you have to have same amount at other side to use static nat.

Static nat leaves port number the same so if source sends traffic out from port 1234 then after static nat source port is still 1234.

In case of Dynamic IP And Port option source port is changed so multiple source IPs can be behind one IP.

 

In your case you have to use Dynamic IP And Port option.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite
Cyber Elite

This will work (bi-directional static nat for a bunch of ip addresses) only if you set your original source addresses to a subnet (not a group object) and the subnet mask needs to exactly match the translation subnet

 

bidir static subnet.png

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper@Raido_Rattameisterthank you for the reply,

 

My goal here is to create Nat rule for two internal servers that go out using the same external IP,

 

Only for outbound direction no bi-directional.

 

I tried to use their IP address /32 and also for the static IP /32 without success.nat rule fail.jpg

 

 

In this case you can't use static-ip.

Choose "Dynamic IP And Port" from droppdown.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

@Raido_Rattameister, for the dynamic IP and port it allows my to apply that Nat rule.

 

How it will behave if those servers are exhcnage servers in DAG design and the outbound traffic is 25 SMTP.

 

Does the smtp traffic will work on the other end? sending emails out?

 

 

@SShnap,

Email systems really don't care about the source-port the traffic is coming from; the traffic just need to hit and open port on the other end. 

  • 1 accepted solution
  • 4825 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!