Security policy and NAT - zone direction

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Security policy and NAT - zone direction

L4 Transporter

Hello Experts

 

When I confiugre the NAT and associated security policy then I always confuse about the direction of zones. As I understand NAT zones are always determined by ingress interface zone (source zone) and route lookup gives the outoing interface zone (destination zone) but my question is when we confiugre the associated security policy then zones direction would be post-nat address zones or pre-nat address zones?

 

1 accepted solution

Accepted Solutions

L6 Presenter

Hi...The security rule is post-NAT so you should use the zones where the actual client/server lives.  Here's a NAT doc for reference:

 

https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Understanding-PAN-OS-NAT/ta-p/60965?attachme...

 

The way I use to remember which zone to use for NAT is:

 

- write the security & NAT rule using the zones where the client & server actually live.

- If this is a dest NAT, then use the zone of the actual client as the source & dest zones in the NAT rule only, not security rule.  Security rule will stay the same as described in previous step

View solution in original post

4 REPLIES 4

L4 Transporter

Hello

 

Is there any one?

L6 Presenter

Hi...The security rule is post-NAT so you should use the zones where the actual client/server lives.  Here's a NAT doc for reference:

 

https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Understanding-PAN-OS-NAT/ta-p/60965?attachme...

 

The way I use to remember which zone to use for NAT is:

 

- write the security & NAT rule using the zones where the client & server actually live.

- If this is a dest NAT, then use the zone of the actual client as the source & dest zones in the NAT rule only, not security rule.  Security rule will stay the same as described in previous step

L6 Presenter

This video helped me to understood the NAT config:

 

https://www.youtube.com/watch?v=aVXzzZEgIA4

 

 

thanks But I am not able to understand that destination NAT happens before security policy so in security policy, we should use the post-nated address (private address) but we use the original public address?

  • 1 accepted solution
  • 3308 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!