- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-05-2013 10:27 PM
Hi Guys
According to document , if there's destination NAT , there'll be second routing lookup to decide outbound zone & interface. But I'm very confused when there's routing and PBF together, In the second routing lookup, how does PBF rule work? Does PBF work based on Pre-NAT destination address or Post-NAT destination address? According to document at the second lookup process works based on POST-NAT destination address, that means if the routing table works fine, it should follow routing table lookup result. But in my customers networks it doesn't look like that.. Using PBF and U-Turn NAT together is really kind of a mess.
Thank you very much.
09-05-2013 10:34 PM
Would any of these docs be of any help?
Understanding PAN-OS NAT
https://live.paloaltonetworks.com/docs/DOC-1517
Packet Flow in PAN-OS
09-05-2013 11:23 PM
Hello,
PBF lookup happens in pre-NAT IP address. Also in PAN firewall NAT evaluate at first with original IP but Apply at the end of flow.
Packet flow on PAN firewall:-
Few more information regarding the same.
Testing Security, NAT and PBF Rules via the CLI
Inbound NAT Policy with Outbound PBF Causing IP-Spoofing Drops
NAT and Security Policies, PBF Failover and Symmetric Return - Dual ISP
Hope this helps.
Thanks
09-06-2013 12:05 AM
Thanks a lot . I'll read these document. Hava a nice day!
04-30-2024 07:47 AM - edited 04-30-2024 08:02 AM
Sorry to revive this 10 years later. Documentation is not specific enough for me. But in my experience:
As I said, official documentation is quite good, but I missed those specific issues.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!