Paloaltonat

Outbound NAT

NAT Policy:

  • Go to Policies/AT
  • Create a new one:

Original Packet:

  • Source Zone: Trust
  • Destination Zone: UNTRUST
  • Destination INterface: Interface associated with Destination Zone
  • Service: Any
  • Source Address: Any or any internal network ranges
  • Destination: Any

Translated Packet Packet: Source Address Translation

  • translation type: Dynamic IP and Port
  • Address type: Interface Address
  • Interface: untrusted interface
  • Ip address: Untrusted inteface IP

Security Policy

  • Create rule allowing traffic from Trust zone to Untrust zone with details you want

DNAT

NAT Policy:

  • Go to Policies/AT
  • Create a new one:

Original Packet:

  • Source Zone: Trust
  • Destination Zone: UNTRUST
  • Destination INterface: Interface associated with Destination Zone
  • Service: Any
  • Source Address: Any or any internal network ranges
  • Destination: Any

Translated Packet Packet: Source Address Translation

  • translation type: Dynamic IP and Port
  • Address type: Interface Address
  • Interface: untrusted interface
  • Ip address: Untrusted inteface IP

Security Policy

  • Create rule allowing traffic from Trust zone to Untrust zone with details you want