- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-12-2024 11:00 AM
Hello friends ,
I am runnng pv-vm on kvm , which has no license presently ,(version 9.0.4)
baiscally this setup is understand palo alto firewall
i have domain /fqdn (want to run all a mx ns server to run locally )
i have setup a web ,mail and ftp and dns server ,web server and ftp server working but need some help/understanting on mail and dns server ,
do i need nat rule or proxy ?
i have configure nat rule but there is problem with over shadows rules which is confusing me
how to setup a u-turn nat when intenal dns server is setup ?
if 9.0.4 does not support submission then which mail it support and how to config it
any reseller pls send me pm/dm
Thanks
09-19-2024 08:58 AM
Hello,
Just like security policies, the firewall reads the rules top-down. So the ones at the top once hit, the rest get disregarded. I would move your more specific NAT policies higher in the list and your more general one to the bottom.
09-13-2024 01:19 PM
Hello,
It all depends on where the traffic is being sourced from and where the servers are located in the network. If you could give us a bit more guidance, we can help you out.
U-Turn rules are used if I want internal clients to connect to the public facing IP of a system. May not be required but it does depend on your environment.
Regards,
09-18-2024 07:18 PM - edited 09-18-2024 07:22 PM
09-19-2024 08:58 AM
Hello,
Just like security policies, the firewall reads the rules top-down. So the ones at the top once hit, the rest get disregarded. I would move your more specific NAT policies higher in the list and your more general one to the bottom.
09-19-2024 09:42 AM
can you please tell me from image i post ,what is wrong ?
if i use internal dns server and dns proxy from palo alto ,does nat rule still shadow down ,(some nat rule doesnt hit )
09-19-2024 09:45 AM
Hello,
Move rule 1 to the bottom of the list.
See if that helps.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!