Monday 10 August 2020

source NAT on palo alto firewall

For the source translation use dynamic-ip-and-port even if you are NAT'ing to a static IP. In the palo world static is only used for 1 to 1 translation.

Switched it to dynamic and issue resolved


src zone: inside

dst zone: MYMAP-30

src: N-10.40.0.0-16

dst: H-10.90.32.44-32

Src translation:

dynamic-ip-and-port

H-172.20.200.1-32


No comments:

Post a Comment