What type of policy\rules do you need to access an internal licenses server from the internet

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

What type of policy\rules do you need to access an internal licenses server from the internet

L3 Networker

I have an internal licenses server that users need to access from the internet, 10.1.3.21.  The The external exposed ip is 216.55.55.10

The application on the users computer needs the following TCP ports open through the firewall so that client workstations are able to obtain a license from your license server system.

lmgrd.exe needs INCOMING TCP ports 27000 to 27009 and adskflex.exe needs 2080.  What is the easiest way to  address this?

We need a natting rule correct?  What type.

Once I figure out the natting rule then I can created policies to allow application traffic on the necessary ports.  Unless there is an exev simpler way to create it all.  Ideas welcome

1 accepted solution

Accepted Solutions

L5 Sessionator

Hello MemphisBrothers

Considering that the license server is in the dmz-L3 zone and the traffic is coming from the untrust-L3 zone, here is how you would go about creating service objects, NAT rule and security rule

Service Objects (Source port kept empty):

Security Rule ( from untrust-L3 to dmz-L3):

NAT Rule ( from untrust-L3 to untrust-L3):

For future reference you refer the following document:

Understanding PAN-OS NAT (Page 19 -21 explains your scenario)

Hope the above configuration helps you.

Thanks and regards,

Kunal Adak

View solution in original post

3 REPLIES 3

L5 Sessionator

Hello MemphisBrothers

Considering that the license server is in the dmz-L3 zone and the traffic is coming from the untrust-L3 zone, here is how you would go about creating service objects, NAT rule and security rule

Service Objects (Source port kept empty):

Security Rule ( from untrust-L3 to dmz-L3):

NAT Rule ( from untrust-L3 to untrust-L3):

For future reference you refer the following document:

Understanding PAN-OS NAT (Page 19 -21 explains your scenario)

Hope the above configuration helps you.

Thanks and regards,

Kunal Adak

Using this as a guide I was able to get what I needed to accomplish.  Thanks a lot. 

L3 Networker

An addendum to this.  Turns out I only needed a rule for inbound traffic only. 

  • 1 accepted solution
  • 4011 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!