06-08-2010 03:28 AM
We have PAN 500 device with us..deployed in L3 mode.Lan and DMZ communication is happening only if i have NAT rule in place with the destination zone and interface mentioned (but no natting be done)between them.Do we really require a NAT rule in place for achieving this.I guess this doesn't require.We have tested with all OS and models.Anyone faced this issue earlier?
06-08-2010 07:54 AM
NAT is not need is your routing is set up correctly.
So if you have a l3 lan interface connected to the same virtual router that a l3 dmz interface is connected to, you should be able to route between them. However if each network does not know how to route back to the other, then you can use a NAT rule to work around your routing problem.
06-08-2010 09:00 AM
We have both the DMZ and trust in the same virtual router and proper routing is there,but the communication is happening only when we have the NAT policy in place.Also sometimes ping,FTP and other services are working but file sharing is not happening,this also only for few users. Have this been replicated in labs and any issues faced earlier?
06-08-2010 09:23 AM
all of what you have described are basic functions of the Paloalto device. So they should work just fine.
As long as you have policies to allow traffic from the trust to dmz or dmz to trust and routing is correct, this should work.
Also sharing should work fine especially if ftp and ping work.
Perhaps you can create a policy for all traffic between the trust and dmz and the dmz and trust, allowing all applications and services.
If committting this policy resolves your issues then you know that perhaps your were not allowing all the necessary applications and services. However if your problems still persist, you can call into support in order that we can take a closer look at your device configuration and network configuration.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!