Double NAT

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Double NAT

L0 Member

Hi!
we have a couple of customer who use paloalto firewalls. We have always problem to connect two accesses through NAT via paloalto. We usually use cisco meraki and the communicate on the higher port numbers. It always work when we have one site that are behind a NAT but when we move the device behind a NAT, it fails.

 

Like this:

    1) NOK: lan<->MX<->NAT<->internet<->NAT<->MX<->lan

    2) OK  lan<->MX<->internet<->NAT<->MX<->lan

 

Everytime we have this issue it end with that the customer use paloalto firewalls.

 

Can someone here explain what it is? or have a configuration solution in paloalto taht can solve this?   

1 REPLY 1

Cyber Elite
Cyber Elite

Can you explain a bit more or draw a diagram with example IP's?

Do those clients have multiple public IP's?

Do you have bi-directional NAT so that traffic destined to this device and sourcing from this device use same IP?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 2287 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!