#PaloAltoTraining

  Рет қаралды 13,483

Bikash's Tech

Bikash's Tech

Күн бұрын

Пікірлер: 39
@z4xarhis
@z4xarhis 2 жыл бұрын
Thank you for the detailed explanation. Very useful for my scenario. I have a website that can be reached by internal users on wifi trust network through internal DNS. External users can reach the website through destination NAT, but internal users on our guest wifi cannot reach the website externally, because it gets assigned external DNS and the firewall doesn't know how to handle the traffic, so it gets dropped. I will be configuring U-turn NAT for guest wifi, so untrusted devices don't query our internal DNS and reach via U-turn policy.
@vinodrajbhar6267
@vinodrajbhar6267 3 жыл бұрын
Way of teaching is very good, thank you for nice content
@anandchandrasekar5253
@anandchandrasekar5253 Жыл бұрын
Very informative, simple and crispy. thank you😀
@ashishsolanki86
@ashishsolanki86 4 жыл бұрын
Hi Bikash, your videos very informative. Just a small request if you can share these eve-ng labs also we can export and work on the same topology. Can you please upload videos for troubleshooting App-ID, content ID, routing and other topics with real world scenarios? Also, waiting for your video on VPN with same subnets. Thanks
@sureshgurumoorthi9853
@sureshgurumoorthi9853 3 жыл бұрын
Very well explained
@praveenbhatt6935
@praveenbhatt6935 2 жыл бұрын
Hlo in interview asked me that if you do not get any traffic logs so how you troubleshoot that what could be the reasons we are not getting any traffic logs
@saurabhchavan3337
@saurabhchavan3337 Жыл бұрын
Please reply on this request
@ameeransar5297
@ameeransar5297 Жыл бұрын
I have a doubt, why we need NAT for internal traffic from inside to DMZ. The source nat mapping happens from private to private which can be achieed simply by creating policy?
@GlobalLadyExplorer
@GlobalLadyExplorer Жыл бұрын
Hi Bikash, thank you so much for giving us so beautiful concept of palo alto... I really appreciate it.. I have a qstn, wot will be the dns and natting resolution if the webserver have public IP taken from an IP pool, I mean if the public dns has mapping with sever domain with the same public ip which is assigned to the web server.. please answer keeping internal dns is not in the private network...
@ashishsolanki86
@ashishsolanki86 2 жыл бұрын
Bikash, if possible share config of both rouetrs also will be very helpful in doing the lab
@AR-dh3yk
@AR-dh3yk 4 жыл бұрын
Is it similar to the concept of TWICE NAT or DOCTORING in CISCO ASA ?
@BikashsTech
@BikashsTech 4 жыл бұрын
I have mentioned in the video asa dns doctoring and twice nat
@rounakjaiswal4216
@rounakjaiswal4216 Жыл бұрын
very informative
@pratikdas538
@pratikdas538 4 жыл бұрын
Hi Bikash Sir , great video but i have a stupid doubt in the video you said the src traffic 10.1.1.1. goes to the server on its public IP 20.1.1.50 which will be NAted to server Private IP - 192.168.1.1 But my doubt is , wont the source IP also be NATTEd to the Fw public Interface to reach th public IP - 20.1.1.50 and hence the retrun traffic will be towards the FW public Interface (which was the NATTed IP for 10.1.1.1 - or any othe NAT that is used for private inside Ips to go to internet) Thanks for these videos , they are really helpful to us
@BikashsTech
@BikashsTech 4 жыл бұрын
thanks for your question, now think when the traffic reach to server, what would be source and destination and when server reply again think about source and destination, how it travel back to source. let me know if you understood.
@abhisheknagpal3172
@abhisheknagpal3172 2 жыл бұрын
@@BikashsTech Hi Bikash , Firstly thanks for the video and yes Pratik is right here as src traffic will also get natted to public ip as per source natting .
@study2master
@study2master 4 жыл бұрын
Greetings from Sadat, Sorry for wondering you Bikash's Tech, If you don't mind please make a complete video on EVE-NG installation and set up all the prerequisites for the Palo Alto Lab. Study2Master
@BikashsTech
@BikashsTech 4 жыл бұрын
Thanks for comment. Hi study2Master, I have already uploaded video on eve-ng Palo Alto lab. if in case it is not informative. please let me know, the points which you did not understand. I will cover in next video. Uploaded video link kzbin.info/www/bejne/naDTc4Bqlq1nfLM
@study2master
@study2master 4 жыл бұрын
@@BikashsTechWhen I'm installing the EVE-NG I do not know where is the problem my VM is not starting asking about Licence and so, If you please make a video from scratch I will appreciate your hard work. Thanks
@dheenadayalan2933
@dheenadayalan2933 9 ай бұрын
good job
@sumanratnalu1717
@sumanratnalu1717 5 ай бұрын
why eth1/3 should not be DMZ zone in NAT configuration ?
@Step2engineerinG
@Step2engineerinG 4 жыл бұрын
Sir, can you start vpn on palo alto firewall. I never understood how make a tunnel in palo alto as well as asa. ASA i have to study amy thing ... Bt palo alto i already have basic knowledge to understand
@Travel_With_Shubham
@Travel_With_Shubham 2 жыл бұрын
Can just share the DNS Router configuration it will be really helpful
@balajipraveen7287
@balajipraveen7287 3 жыл бұрын
Hi, could you please do video for palo alto d nat from outside to inside please..
@srikarpuligandla3769
@srikarpuligandla3769 2 жыл бұрын
Hi Bikash, does unat applies to traffic coming from outside to dmz or it’s just dnat applies here? I have understood from inside to dmz for external dns server but bit confused for outside to dmz.
@shwetankmishra6870
@shwetankmishra6870 2 ай бұрын
Hi Sir, is it U Turn an exceptional case ? means , if we have internal DNS Server configured , then internal users can directly connect with internal server without need of public ip?
@BikashsTech
@BikashsTech 2 ай бұрын
Yeah
@amarjeetkumar8735
@amarjeetkumar8735 2 жыл бұрын
This is only for source NAT not for DNAT. Correct me if wrong.
@mdabdulmoiz
@mdabdulmoiz 4 жыл бұрын
for this u turn nat you mean source is pc dest is webserver outside ip (so pc without natting going out with its lan ip?) then hitting wan ip of server then going to 192.168.1.1 source ip lan can go out without nat? and return is directly going from dmz to in ? where is unnat happening first , bro is there any other video of you on this?
@kaung5628
@kaung5628 2 жыл бұрын
Can i configure U-trun NAT with two public ip addresses ?
@heshekar
@heshekar 4 жыл бұрын
kinldy do DNS sinkholing Video
@mdabdulmoiz
@mdabdulmoiz 4 жыл бұрын
how is the packet flow? pc going out to DNS then coming back to GlobalIP which is forwarding to DMZ?
@BikashsTech
@BikashsTech 4 жыл бұрын
Hi Abdul, Thanks for comment. Yeah, without DNS how PC will reach webserver, once the dns resolution happens, PC will try to access the webserver then NAT will perform which is know as u-trun NAT.
@minoshpm8052
@minoshpm8052 4 жыл бұрын
Sir can you please mention here what ip is 192.x.x.1 and 192.x.x.10....juta need to know which interface and server ip is this....I think there will be one ip that is 192.168.1.1 that's the internal dmz server..so what is 1.10 coming frm please clear me
@BikashsTech
@BikashsTech 4 жыл бұрын
Hi Minosh, Thanks for comment, i think, you have still not understand. We are doing twice nat (Source and destination both are getting NATTED) so, 192.168.1.10 is gateway of server (palo alto interface IP of DMZ) and 192.168.1.1 is PC IP.
@minoshpm8052
@minoshpm8052 4 жыл бұрын
@@BikashsTech thank you sir....🙏
@nitinjayswal1527
@nitinjayswal1527 3 жыл бұрын
Itna confuse kr dya ki kya btau
@BikashsTech
@BikashsTech 3 жыл бұрын
Thanks for comment. Hahahaha.. U-trun is easy to configure, if understand concept and to understand the concept, you need to know how DNS works.
@nitinjayswal1527
@nitinjayswal1527 3 жыл бұрын
@@BikashsTech no you are doing a great job i went through so many videos of yours but i felt this one is bit messy and mixed up...
快乐总是短暂的!😂 #搞笑夫妻 #爱美食爱生活 #搞笑达人
00:14
朱大帅and依美姐
Рет қаралды 12 МЛН
СКОЛЬКО ПАЛЬЦЕВ ТУТ?
00:16
Masomka
Рет қаралды 3,4 МЛН
The IMPOSSIBLE Puzzle..
00:55
Stokes Twins
Рет қаралды 173 МЛН
U Turn NAT | Why and how do we configure it | Palo Alto firewall
15:03
U Turn NAT: How to configure U turn NAT in Palo Alto  (in Hindi)
11:22
快乐总是短暂的!😂 #搞笑夫妻 #爱美食爱生活 #搞笑达人
00:14
朱大帅and依美姐
Рет қаралды 12 МЛН