I'm trying to set up a fairly simple configuration where we have our separate wired and wireless networks connecting to the internet via one shared interface eth1/1 Basically, I am attempting to replicate the configuration here https://live.paloaltonetworks.com/docs/DOC-1884 (but with only 2 local networks, not 3). This document stresses that explicit NAT rules must be set up, but does not give an example on how to do this. I have set up untagged sub interfaces, the virtual routers, policies and what I believe to be the correct NAT policies. I know these are correct because if I only set up one sub interface everything is OK. As soon as I set up a second subinterface and hook it up to the virtual router, traffic stops flowing. I am assuming that is because I have not created the NAT policy correctly. Please can somebody provide an example NAT policy for an untagged subinterface. Thanks.
... View more