Global Protect at the inside truted interface

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect at the inside truted interface

L3 Networker

PAN 5060

Outisde untrusted interface 5.5.1.77

Inside trusted interface 10.10.1.1

 

Wifi guest network inside 10.10.5.0/24

 

Most Global Protect corporate users go to ourvpn.foo.com 5.5.1.77.

 

WiFi users normally PAT to the Internet using that same interface IP 5.5.1.77. So all source addresses to the Internet appear to be 5.5.1.77. Like most guest networks the users have no access (for the most part) to internal IP private addresses. Just Internet.

 

But let's say that WiFi user 10.10.5.99 wants to to user Global Protect like the outside users so he can access internal resources. Is there a NAT that would say if you see traffic from the WiFi network destined for the external interface address 5.5.1.77 at VPN port whatever - instead of PATting it, terminate that traffic and create the tunnel just as is it had originated from the outside untrusted network. Is that possible? 

 

Thank you.

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

hi @palomed

you'll need a NAT rule at the top of your NAT policy that actually does not do NAT for that specific destination address

 

 

so

trust to untrust, destination ip 5.5.1.177 no-NAT

nonoat.png

make sure it is placed above your default outbound NAT

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

hi @palomed

you'll need a NAT rule at the top of your NAT policy that actually does not do NAT for that specific destination address

 

 

so

trust to untrust, destination ip 5.5.1.177 no-NAT

nonoat.png

make sure it is placed above your default outbound NAT

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Very helpful. Thank you.

  • 1 accepted solution
  • 1903 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!