Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Many-to-Many NAT (Both Direction)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Many-to-Many NAT (Both Direction)

L1 Bithead

Hi Everyone, 

 

I am struggling to solve a problem NAT issue and need some help. I need to configure May-to-Many NAT on Palo Alto Firewall  between two data centers. I have three /25 IPv4 subnets which needs to be mapped to three /25 subnets (subnet to subnet basis if not one to one IP basis) and three IPv6 /40 subnets needs same treatment. Traffic is expected to come from both direction inside to outside and outside to inside on specified TCP, UDP and ICMP ports. I have PA3220 which has been upgraded to PAN OS 9.0 and I will applicate if you can suggest best way to achieve this? Do I need to consider any resource limitation as I have three /25 IPv4 and three /40 IPv6 subnets which can overwhelm the resource? 

 

Thanks

RT

8 REPLIES 8

Cyber Elite
Cyber Elite

Hello,

How are the two data centers connected? Just curious as to why you need the NAT?

 

Regards,

Yes they are connected but part of Migration work and removing Overlapping addresses requires NAT. 

Thank you for the prompt reply. I will check your suggested solution. In the meantime please could you tell me if it possible to solve by NAT or its impractical?  

While I have not had to do this. The articles go into this using NAT when you have the same subnets on the both sides.

I do have similar challenges due to migration work hence wanted to employ NAT as traffic is expected both ways between subnets hence NAT seems good option.   

All,

 

I have noticed when Destination NAT configured for IPs which aren't configured on Firewall packets are being dropped so /25(IPv4)  and /40(IPv6). If I add subnet as a Loopback interrace on firewall then NAT works. I tried using static discard route (Null route) but its not solving the issue. I am guessing its proxy-arp issue or is it something else? Any other way to solve the issue? 

 

 

L2 Linker

I would do this using several NAT rules (one for each subnet).  See the third example on the static NAT section for use with subnets.  (I have also configured and tested this in the past)

 

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/source-nat-and-destination-...

 

 

  • 6352 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!