Hello, I'm having issues with 1:1 NAT set up. Using a pair of PA-5220s in Active/Passive set up. I need to set up temporary access to some devices behind the firewall. I have a block of IPs I can use. Do I need to set an IP from that block on an interface? The block I have is being routed to the primary IP of the firewall right now. What I'm trying to accomplish is: Public IP-1> 10.9.20.143 (with 5 ports) Public IP-2> 10.9.20.144 (with same 5 ports) public IP-3> 10.9.20.155 (only one port) Then would I need a separate rule for each NAT policy?
... View more