- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-29-2016 07:54 AM
Hello Experts
I was checking confiugration on my PA firewall and I foud for every source and destination NAT, the public IP for NAT with /32 was assigned to external interface of firewall. In my opinion there is no need to assign public IP /32 to external interface of firewall? Can any body explain to me this
10-30-2016 05:38 AM
Palo Alto NAT rules will automatically create the proxy-arp if the address is withing the subnet range of your existing external interface. The address would not need to be added to the interface for this to work.
10-30-2016 05:38 AM
Palo Alto NAT rules will automatically create the proxy-arp if the address is withing the subnet range of your existing external interface. The address would not need to be added to the interface for this to work.
11-05-2016 12:05 PM - edited 11-05-2016 12:10 PM
thank you but what we need to do if public pool range isin different range than external interface subnet range? Firewall will also do the proxy-arp for this
11-06-2016 03:42 AM
If your ISP is routing the subnet to your PA interface as the next hop, then no proxy-arp will be needed.
If your ISP has added the second subnet to their interface and given you a second gateway address, then you need to add an address in this subnet and mask to your interface. Then the necessary proxy arp will be created when you add the NAT rules.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!