Chapter 1. Basics
1.3 SNAT
Learning Objectives
- Configure Source NAT (SNAT)
Prerequisites:
- Security policy for Inside to Outside
- Interface configuration
- Knowledge of previous labs
data:image/s3,"s3://crabby-images/7e97d/7e97d47837add8d5ed5d8f5d822af1bb5afb89be" alt="Main Scenario"
Device | Configuration |
---|---|
Clint | eth0: 10.0.0.2/24 GW: 10.0.0.1 DNS: 8.8.8.8 |
PaloAlto | Ethernet1/1: 10.0.0.1/24 Ethernet1/2: DHCP Management: 192.168.0.1/24 |
Management (WebTerm) | eth0: 192.168.0.2/24 |
Outside (WebTerm) | eth0: DHCP |
Zone | Interface |
---|---|
Inside | Ethernet1/1 |
Outside | Ethernet1/2 |
SNAT (Source NAT: Access the Internet in Palo Alto)
Under the policies tab, go to NAT, then click Add.
data:image/s3,"s3://crabby-images/2ddca/2ddca0890715f3eeb6aad84ea112f52c5cedae4a" alt="Set a Source NAT"
We want to translate packets originating from the Inside to go to the outside zone using the interface address of ethernet1/2. This would be Port Address Translation Overload. Under the General tab, just change the name.
data:image/s3,"s3://crabby-images/06b55/06b556432dfdd3ad8964c08d2e737d4e8ac67aff" alt="Set a Name for NAT"
Under the original packet tab, click add then make the source zone inside. As for the destination zone, make it outside.
data:image/s3,"s3://crabby-images/5758f/5758f1640b48118a0a40e8a80264496a439ad95d" alt="Set a Source Zone and Destination Zone for NAT"
Configure these settings under the translated packet tab in the source address translation area:
Parameter | Value |
---|---|
Translation Type | Dynamic IP and Port |
Address Type | Interface Address |
Interface | Ethernet1/2 |
IP Address | None |
data:image/s3,"s3://crabby-images/d7af3/d7af33aba2852e0fe98dce66b7f0ad524d224127" alt="Set a Translated Packet"
Don’t forget to commit!
Check Internet Connectivity on Webterm
Open up webterm, and navigate to any website of your choosing.
data:image/s3,"s3://crabby-images/e4e73/e4e738f10038c30ecd501d2643b2740b23c7042c" alt="Verify your connectivity to the Internet"
If your desired webpage showed up, you have successfully configured SNAT!