- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-06-2024 03:37 PM
Hello,
I have two Pa-440's. One 440 has a public static ip and the other is just dhcp as of right now. I do a site to site to site vpn working between them.
I setup an original port forward on the public static ip device to a local host and it worked great. Now, I moved that host to a subnet on the public dhcp firewall. I tried switching the port forward to the new ip at the remote location across the tunnel interface, but it never seems to work. Is this possible to do?
Bryan
05-07-2024 08:38 AM
Hi @btolkawfp ,
You can modify the same rule to NAT the source IP to 10.10.10.10.
Thanks,
Tom
05-06-2024 04:20 PM
Hi @btolkawfp ,
NAT over VPN is definitely possible.
Thanks,
Tom
05-06-2024 05:48 PM
1.) The site to site between firewalls is working
2.) the destination zone of the port forward is untrust and untrust
3.) no failed logs ..just says incomplete.
the issue is getting the client using the public ip and then natting that request through a vpn tunnel and then back to the original firewall.
05-06-2024 06:18 PM
Of course!
You will also need to do a source NAT to a prefix on the public static IP FW so that the return traffic is routed back. The easiest way to do it is put IP addresses on your tunnel interfaces (one on each side) and source NAT to the tunnel IP. The prefix on the tunnels can be a /30 or even a /31.
Thanks,
Tom
05-07-2024 04:38 AM - edited 05-07-2024 08:18 AM
ok that makes more sense.. i am still having a hard time visualizing that source nat configuration. Here is port forward rule.
I added a tunnel interface of 10.10.10.9/30 to the public dhcp firewall and 10.10.10.10/30 to the static firewall
Thanks for your help.
05-07-2024 08:38 AM
Hi @btolkawfp ,
You can modify the same rule to NAT the source IP to 10.10.10.10.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!