Possible NAT issue on a PA-3260

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Possible NAT issue on a PA-3260

L1 Bithead

Folks, I am trying to configure a NAT policy which should be bi-directional. Here the traffic can be initiated from outside or the inside. The policy is configured and I can see NAT hits. However, this policy does not work.

 

The NAT IP is from a subnet which does not reside on the Untrust interface. This is where I see the possible challenge is. The reason to say this is that the PA does not show the NAT IP in it ARP database.

 

Is there some dedicate configuration required on the PA that announces this NAT IP belongs to the PA? Here is an article I found and wanted to run it through the community.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGZCA0

 

Regards,

N!

3 REPLIES 3

Cyber Elite
Cyber Elite

@tech_geek2023,

The article has the three ways that you can fix this. The vast majority of the time I see people just create a route for the traffic to get around this instead of assigning secondary IPs or utilizing loopbacks or anything like that; just add a route for your public IP range that you'll be using to NAT addresses and you'll be good to go. 

I tried the route addition as well but it has not helped. Any other suggestions or comments on this?

Cyber Elite
Cyber Elite

if you need to 'own' ip addresses on an interface without adding them to said interface, you can use an inbound NAT rule with 'original destination' set to those IP addresses. the firewall will then proxy arp for those IP's

 

the rule would be something like:

from untrust

to untrust

destination interface <external interface>

original source any

original destination <the IP you want to proxy-arp e.g. 198.51.100.1>

translated destination <the internal IP e.g. 10.0.0.1>

 

a ticked "bi-directional" check box may not suffice to get proxy-arp to work for not-attached IP addresses

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 526 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!