Inbound NAT - Please advise

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Inbound NAT - Please advise

Not applicable

Hi,

Consider the following:

All traffic (0.0.0.0/0) is NAT'd as 1.1.1.1 (public)

The exchange server has an inbound NAT of 1.1.1.2 (public) > 192.168.1.1 (private).

Now when the exchange server makes a connection to the outside world will it be seen as 1.1.1.1 or 1.1.1.2?

If it is 1.1.1.1, then I must make a reverse NAT rule for all my inbound VIPs to that they respond to INBOUND VIP and are seen as INBOUND VIP.

Please advise.

1 REPLY 1

L6 Presenter

Sunny,

You can configure STATIC Bidirectional rule for your exchange server so that it cares of both the inbound / outbound connections related to the server. In that case the server would use 1.1.1.1 for outgoing connections. Then below this rule you would place a rule for your internet traffic.

Here is a good doc

https://live.paloaltonetworks.com/docs/DOC-1517

  • 1780 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!