Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    no incoming traffic

    Scheduled Pinned Locked Moved IPsec
    15 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      moisesdasilvadeoliveira @viragomann
      last edited by

      @viragomann

      The sense of doing binat is because my client doesn't allow me to arrive with my lan /24 and asks me to translate the address to a /29. So, as my lan is /24, I only get an ip from the /29 network and translate it to his destination network.

      V 1 Reply Last reply Reply Quote 0
      • M
        moisesdasilvadeoliveira @viragomann
        last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • V
          viragomann @moisesdasilvadeoliveira
          last edited by viragomann

          @moisesdasilvadeoliveira
          Ok. But this allows either bidirectional communication to a /29 part or your network or a unidirectional communication from your whole network using a single BINAT address.

          1 Reply Last reply Reply Quote 0
          • M
            moisesdasilvadeoliveira @viragomann
            last edited by

            @viragomann

            bd68d4a0-4542-4266-adbb-30f58e6bfd86-image.png

            My Lan 172.31.10.0/24
            network that my client wants me to get there 10.188.176.248/29.
            Destination network 10.216.0.0/27
            As my lan is /24
            I get an ip from his /29 (10.188.176.248/29), so I use 10.188.176.249, but I can use 10.188.176.250 or the next

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @moisesdasilvadeoliveira
              last edited by

              @moisesdasilvadeoliveira
              Select "network" at BINAT and enter the network address which is 10.188.176.248 and /29 for the mask.

              M 2 Replies Last reply Reply Quote 0
              • M
                moisesdasilvadeoliveira @viragomann
                last edited by

                @viragomann

                The scenario is as follows.

                I have a lan that is 172.31.10.0/24, I have several servers on this lan. My client will not have access to it, only a zabbix-proxy within that lan.
                I need to connect to several servers of my client, we have several tunnels, some for a /27 network, others for a specific host /32
                with that he asks me to arrive with the subnet /29.

                I still have a second subnet /24, this one comes from my openvpn, that is, I have a vpn s2s, which all my employees will access to support the customer, and for that they used openvpn.
                ce52ea38-7956-4c5a-88ef-4bb3527ddc2a-image.png

                V 1 Reply Last reply Reply Quote 0
                • M
                  moisesdasilvadeoliveira @viragomann
                  last edited by

                  @viragomann said in no incoming traffic:

                  Select "network" at BINAT and enter the network address which is 10.188.176.248 and /29 for the mask.

                  M
                  1 Reply Last reply less than a minute ago Reply

                  I can't do this because my lan is /24 and my snat(binat) /29

                  1 Reply Last reply Reply Quote 0
                  • M
                    moisesdasilvadeoliveira
                    last edited by

                    I have this same scenario with other clients, working in the same way, but it is not a palo alto, I have cisco asa, edegerouter, all of them working with the same scenario.
                    Using my lan /24
                    they asking me to arrive with snat(binat) /29
                    arriving on any network within my client..
                    Everything functional.
                    But in Paloalto this is not happening.

                    1 Reply Last reply Reply Quote 0
                    • V
                      viragomann @moisesdasilvadeoliveira
                      last edited by

                      @moisesdasilvadeoliveira said in no incoming traffic:

                      I have a lan that is 172.31.10.0/24, I have several servers on this lan. My client will not have access to it, only a zabbix-proxy within that lan.
                      I need to connect to several servers of my client, we have several tunnels, some for a /27 network, others for a specific host /32

                      Maybe you can realize this with 2 phase two tunnels. One for the connection to the Zabbix with its single address as "local network" and a single address out of the /29 you got.
                      And a second p2 with your LAN as local network and another single BINAT address of the /29.
                      However, I'm afraid that the Palo Alto doesn't accept this setup. Some firewalls do.

                      I can't do this because my lan is /24 and my snat(binat) /29

                      I mentioned your options in former posts already.

                      I have this same scenario with other clients, working in the same way,

                      A BINAT with some to many? So again the question, how would the remote site be able to access a certain IP on your site??

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        moisesdasilvadeoliveira @viragomann
                        last edited by

                        Hello @viragomann

                        Thanks for the responses and attempts to help. We found the problem. On the client side he needed to enable nat-t. After adjustment, communication worked normally. Thank you very much

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.