Tutorial: Understanding the NAT/Security Policy Configuration

preview_player
Показать описание
This tutorial will clarify the configuration relationship between NAT policy rules and Security Policy rules and which values to configure for each. This tutorial provides a structured/consistently repeatable method for creating NAT (especially destination NAT) rules and corresponding Security Policy rules. If you have ever heard the term “pre-nat IP, post-nat zone” and been confused, this video will clarify that saying. This tutorial will also explain the behavior of Bi-directional NAT rules and when it is appropriate to use them.
Рекомендации по теме
Комментарии
Автор

I just spent a week in Texas for the PAN CSL training and had the pleasure of having Mark teach the first two days. Mark was fantastic and I learned a lot. This is a great video. It will really help you understand how NAT works in the Palo world.

BobBagheri
Автор

Hats off for such a beautiful and simple explanation Mark

Kaal_Bhairava
Автор

I'm going to add my two cents and say that this video is very helpful in understanding NAT/Security policy configurations. Searching YouTube for instructional videos on PA can be frustrating due to quality of videos and language/accent. So I enjoyed the clarity of the speaker and his overall knowledge of the subject. Thank you Mark!

siddeeq
Автор

This is by far the best explanation of the most dreaded concept i.e. NAT

farhanbutt
Автор

was searching for video to understand D-NAT, Finally landed and found this video, Great detailed tutorial.. Thank you so much for such a awesome job. 10/10 ratings.

RahulKumar-hsos
Автор

The best explanation of this that I’ve ever seen. Thank you

Mistandersn
Автор

Thank you, Mark. Now I have a clear picture of how the NAT and security policy works.

Black_Swan
Автор

Super helpful. Prior to watching the video I was seriously confused

nikkycooly
Автор

Great video, cleared up all of my confusion. I only wish the official training was like this, instead of (mostly) a robotic voice sloooowly reading from slides. Thanks!

samual
Автор

Well Explained Mark Bowling. The checklist way of configuration one step after the other. Perfect one. Thank you.

mailgowthamkumar
Автор

Damn!! This video was on point especially the section before describing the lazy function of the bi-directional check box. I loved the explanation of explaining the subtleties of a NAT policy versus a Security Policy. I was actually doing this subliminally with regards to routing internal to the public/global address of my DMZ firewalls, but this video helped a YUGE TONNE, LIKE YOU COULDN'T IMAGINE!!! Thank you Firewall Master Mark!!! #PaloAltoNetworks

omarquintanilla
Автор

really what i was looking for. i was a bit confused on how things works in PA devices. thanks a lot man :)

ervinskendaj
Автор

Perfect u-turn explanation, and more. great video!

Grips
Автор

We're happy this video has helped so many. Thank you for the kudos! Also check out the Live Community at live.paloaltonetworks.com for more info -- feel free to post your questions there, too!

PaloAltoNetworksLiveCommunity
Автор

Very easy to understand the way it's explained here Thanks much

jamessullo
Автор

Mark you're a beast. Thanks for your video!

Xevious
Автор

Awesome video...very very helpful.just to add a point if default intrazone policy has a clean up rule on top of it(few customers do insist for this)then we also have to create a rule for untrust to untrust in order to allow this.

Navachakshu
Автор

Great video... He give a very clear understanding.

steel
Автор

thanks dear sir for uploading your training videos

nasratshah
Автор

Thanks much, Mark, for this simple direct explanation. I understand how the Palo Alto works, but I could never explain it in any way that made sense to someone else. One question: how are you able to get traffic from the internal zone to bypass NAT rule #1, which watches for any destination traffic, and process on NAT rule #3 ("Server 1 from Inside" - Internal > Internet > translated DMZ zone)?

winsyrstrife