04-09-2021 06:01 AM
Hi Everyone,
I am struggling to solve a problem NAT issue and need some help. I need to configure May-to-Many NAT on Palo Alto Firewall between two data centers. I have three /25 IPv4 subnets which needs to be mapped to three /25 subnets (subnet to subnet basis if not one to one IP basis) and three IPv6 /40 subnets needs same treatment. Traffic is expected to come from both direction inside to outside and outside to inside on specified TCP, UDP and ICMP ports. I have PA3220 which has been upgraded to PAN OS 9.0 and I will applicate if you can suggest best way to achieve this? Do I need to consider any resource limitation as I have three /25 IPv4 and three /40 IPv6 subnets which can overwhelm the resource?
Thanks
RT
04-09-2021 08:00 AM
Hello,
How are the two data centers connected? Just curious as to why you need the NAT?
Regards,
04-09-2021 08:34 AM
Yes they are connected but part of Migration work and removing Overlapping addresses requires NAT.
04-09-2021 08:44 AM
Hello,
Please check out these articles and see if they help out.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLTlCAO
Regards,
04-09-2021 08:53 AM
Thank you for the prompt reply. I will check your suggested solution. In the meantime please could you tell me if it possible to solve by NAT or its impractical?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!