- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-29-2016 07:57 AM
Hello Experts
Someone from PA told me that for public service like email server, where bidirectional NAT is required, it is best practice to use source NAT and destination NAT for the same public IP instead of using static NAT because static NAT will create the rule from every zone to server zone NAT. Can any body confirm this, really it is a best practice then why PA created the conecept of static NAT. Strange !
10-30-2016 05:42 AM
NAT and security policy are completely separate in PanOS. Creating a static NAT rule will not permit any traffic by itself there needs to be a security policy to allow that connection to occur.
Here is the actual recommended NAT configuration guide. I see no mention of avoiding static NAT.
https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Understanding-PAN-OS-NAT/ta-p/60965
10-30-2016 05:42 AM
NAT and security policy are completely separate in PanOS. Creating a static NAT rule will not permit any traffic by itself there needs to be a security policy to allow that connection to occur.
Here is the actual recommended NAT configuration guide. I see no mention of avoiding static NAT.
https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Understanding-PAN-OS-NAT/ta-p/60965
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!