- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-18-2017 02:29 AM
Hi all.
How do I settings NAT and Application Override?
PC-A :201.xx.xx.182
|
Palo :210.xx.xx.168
:210.xx.xx.169 -> 192.168.1.10 and TcpTimeout 4000ms
:192.168.1.1
|
Server-A :192.168.1.10
Set Policy is
Allow From 201.xx.xx.182 To 210.xx.xx.169 HTTPS, and NAT To 192.168.1.10.
OverRide is
From 201.xx.xx.182 To 210.xx.xx.169 HTTPS?
or
From 201.xx.xx.182 To 192.168.1.10 HTTPS?
Which one?
Thank you.
10-18-2017 09:10 AM - edited 10-18-2017 09:11 AM
Policies should be configured wit pre-nat IP, post-nat zone.
So From 201.xx.xx.182 To 210.xx.xx.169 HTTPS
10-18-2017 02:59 AM
Hi awawa100,
NAT takes place separately to App-ID (app override). You can find full details in the packet flow document here:
https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081
hope this helps,
Ben
10-18-2017 04:23 AM
Thank you Ben.
What do I chioce one?
10-18-2017 09:10 AM - edited 10-18-2017 09:11 AM
Policies should be configured wit pre-nat IP, post-nat zone.
So From 201.xx.xx.182 To 210.xx.xx.169 HTTPS
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!