- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-01-2013 05:56 AM
An over-simplified explanation of my setup. Trust me, it just has to be this way.
ethernet1/1 - Internet 1.2.3.1/24
ethernet1/2 - LAN 10.10.10.1/24
Nat/dnat/1-1 nat between ethernet 1/1 and 1/2
I have a traffic shaping appliance that I need to loop data through BEFORE NAT on the palo.
Trust me when I say I just cant stick it between the lan and palo. In a nutshell, I have multiple virtual systems that all need to be looped through the shaper in a complex network. Only data destined for the internet should go through the traffic shaper.
I WANT to do this:
ethernet1/1 - Internet 1.2.3.1/24
ethernet1/2 - LAN 10.10.10.1/24
ethernet1/3 - 10.0.0.1/30 Shaper Internal side, in LAN zone
ethernet1/4 - 10.0.0.2/30 Shaper External side in LAN zone
The shaper is transparent. It would be the same as ethernet1/3 and 1/4 being patched together.
Policy forwarding.
Anything outbound to internet from lan zone, next hop 10.0.0.2 egress interface ethernet 1/3
Anything coming in from internet zone to lan, next hop 10.0.0.1 egress interface ethernet 1/4
I tried this once with to virtual routers in the vsys and routing between them. It didnt work as I expected. I stopped there and figured I would ask if im barking up the wrong tree and it just isnt going to work.
Input welcome! Thanks!
04-01-2013 07:38 AM
I think I figured what I was doing wrong. I think the policy was matching on return from the packet shaper and being sent through it again until TTL expired.
04-01-2013 07:38 AM
I think I figured what I was doing wrong. I think the policy was matching on return from the packet shaper and being sent through it again until TTL expired.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!