Multiple NAT and Private IP Addressing - Help Needed

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Multiple NAT and Private IP Addressing - Help Needed

Hi,

I'm relatively new to PA firewalls, so please forgive me if this is not explained well.

I have a PA-500 with PANOS 5.0.0. Im using three interfaces at present - e1/1 - internal network, e1/2 - Internet untrust, e1/3 internet untrust (private ip 169.254.0.1/32)

At present I have my rules configured and my NAT commands for my internet connection on e1/2 and this works fine. Both e1/1 and e1/2 are under a single virtual router, which also has an 0.0.0/0 route outbound. On this connection I have NAT inbound mapping ssl and other services to internal servers on the internal network (192.168.1.x) with no problems.

However, it happens that our email is delivered on the second internet connection, which is government-based, and uses a private addressing scheme.

I set up this connection as like the first, and added it to the default VR - cloned the nat policies and security policies, and changed the pointers. However no mail will come inbound. Furthermore, I cannot ping anything on this 169.254 range. Ive double-checked the NAT statements and all seem in order.

In the first instance I thought that maybe my addresses were being translated by the first nat rule, so I added a nat translation only applicable to connections going to that network on 169.254.x.x, and ran the check NAT commands via the command-line. All checked out and the nat was being translated into the 169.254.x.x address on e1/3 correctly.

Im at a huge loss as to why the email is not being mapped to the mail server. every now and then in my logs I notice an allow from the mailserver on this network coming into my mailserver, but the connection is being listed as incomplete, and the logs only show up if the rule is set to log at end - no corresponding start of the connection can be seen.

I then tried a separate VR for this network but have not finished it yet as Ive no internal interface to add  - perhaps using a loopback might work?

Anybody have issues with NAT inbound from an external private ip address such as this?

Many thanks in advance.

Ger

1 REPLY 1

L6 Presenter

Hi Gerald,

Please refer following document page7, it confirms Martian packets are not supported.

Packet Flow in PAN-OS

Following page confirms 169.254.0.1/32 belongs to martian IP.

Martian packet - Wikipedia, the free encyclopedia

Let me know if you have more questions on this.

  • 1823 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!