Communication Problem between Lan and DMZ

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
Not applicable

Communication Problem between Lan and DMZ

Hi,

We have PAN 500 device with us..deployed in L3 mode.Lan and DMZ communication is happening only if i have NAT rule in place with the destination zone and interface mentioned (but no natting be done)between them.Do we really require a NAT rule in place for achieving this.I guess this doesn't require.We have tested with all OS and models.Anyone faced this issue earlier?

Highlighted
L4 Transporter

Hello Veera,

NAT is not need is your routing is set up correctly.

So if you have a l3 lan interface connected to the same virtual router that a l3 dmz interface is connected to, you should be able to route between them. However if each network does not know how to route back to the other, then you can use a NAT rule to work around your routing problem.

thank you,

Stephen

Highlighted
Not applicable

Hi STEPHEN,

We have both the DMZ  and trust in the same virtual router and proper routing is there,but the communication is happening only when we have the NAT policy in place.Also sometimes ping,FTP and other services are working but file sharing is not happening,this also only for few users. Have this been replicated in labs and any issues faced earlier?

Thanks,

veera

Highlighted
L4 Transporter

Hello Veera,

all of what you have described are basic functions of the Paloalto device. So they should work just fine.

As long as you have policies to allow traffic from the trust to dmz or dmz to trust and routing is correct, this should work.

Also sharing should work fine especially if ftp and ping work.

Perhaps you can create a policy for all traffic between the trust and dmz and the dmz and trust, allowing all applications and services.

If committting this policy resolves your issues then you know that perhaps your were not allowing all the necessary applications and services. However if your problems still persist, you can call into support in order that we can take a closer look at your device configuration and network configuration.

thanks,

Stephen

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!