{"id":410,"date":"2026-08-09T11:00:02","date_gmt":"2026-08-09T05:30:02","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/palo-alto-source-nat-configuration\/"},"modified":"2026-09-14T04:40:47","modified_gmt":"2026-09-13T23:10:47","slug":"palo-alto-source-nat-configuration","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-source-nat-configuration\/","title":{"rendered":"Palo Alto Source NAT Configuration with a Real-Life Internet Access Example"},"content":{"rendered":"<p>In enterprise firewall deployments, internal networks almost always use private RFC 1918 IPv4 addresses. Because public internet routers discard non-routable private addresses, outward-bound traffic requires source network address translation. Understanding <strong>Palo Alto Source NAT configuration<\/strong> is an essential skill for security engineers implementing outbound internet connectivity.<\/p>\n<p>This tutorial provides a step-by-step guide to configuring, verifying, and troubleshooting Source NAT on a Palo Alto Networks firewall. You will learn how to configure Dynamic IP and Port (DIPP) translation to map an entire internal subnet to a single public IP address assigned to the firewall interface.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>Acme Corp needs to provide outbound internet access for employee workstations located on an internal subnet. The company has a single static public IPv4 address assigned by its Internet Service Provider (ISP) to the external firewall interface.<\/p>\n<p>The technical requirements are as follows:<\/p>\n<ul>\n<li>Translate internal clients on <code>192.168.10.0\/24<\/code> to the firewall external public IP address when accessing the internet.<\/li>\n<li>Allow multiple internal hosts to share the single external public IP address simultaneously using port multiplexing.<\/li>\n<li>Ensure security policy rules correctly evaluate traffic matching the NAT policy.<\/li>\n<li>Log outbound sessions for auditing and troubleshooting purposes.<\/li>\n<\/ul>\n<h2>Lab Topology<\/h2>\n<p>The topology below illustrates the physical and logical flow of traffic from the internal client workstation, through the firewall, to the external ISP gateway and internet destination.<\/p>\n<pre>\n+------------------------------------+\n| Internal Client (LAB\/EXAMPLE)      |\n| IP: 192.168.10.50\/24               |\n| Gateway: 192.168.10.1              |\n+-----------------+------------------+\n                  |\n                  | Trust Zone\n                  v\n+-----------------+------------------+\n| Palo Alto Networks Firewall        |\n| Interface: ethernet1\/2 (Trust)     |\n|   IP: 192.168.10.1\/24              |\n|                                    |\n| Interface: ethernet1\/1 (Untrust)   |\n|   IP: 203.0.113.2\/24 (Public)      |\n+-----------------+------------------+\n                  |\n                  | Untrust Zone\n                  v\n+-----------------+------------------+\n| ISP Gateway Router                 |\n| IP: 203.0.113.1\/24                 |\n+-----------------+------------------+\n                  |\n                  v\n       Internet Destination\n       IP: 198.51.100.20\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>All network addresses, zone names, and object names used in this guide are laboratory examples. You must adapt these values to match your specific production deployment.<\/p>\n<table>\n<thead>\n<tr>\n<th>Element \/ Object Name<\/th>\n<th>Type<\/th>\n<th>Value \/ Address<\/th>\n<th>Purpose<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Trust<\/strong><\/td>\n<td>Security Zone<\/td>\n<td>Layer 3 (ethernet1\/2)<\/td>\n<td>Connects to the internal LAN segment<\/td>\n<\/tr>\n<tr>\n<td><strong>Untrust<\/strong><\/td>\n<td>Security Zone<\/td>\n<td>Layer 3 (ethernet1\/1)<\/td>\n<td>Connects to the external ISP link<\/td>\n<\/tr>\n<tr>\n<td><strong>ethernet1\/2<\/strong><\/td>\n<td>Physical Interface<\/td>\n<td><code>192.168.10.1\/24<\/code><\/td>\n<td>Default gateway for internal hosts<\/td>\n<\/tr>\n<tr>\n<td><strong>ethernet1\/1<\/strong><\/td>\n<td>Physical Interface<\/td>\n<td><code>203.0.113.2\/24<\/code><\/td>\n<td>Public-facing WAN interface<\/td>\n<\/tr>\n<tr>\n<td><strong>net-192.168.10.0_24<\/strong><\/td>\n<td>Address Object<\/td>\n<td><code>192.168.10.0\/24<\/code><\/td>\n<td>Defines the internal network segment<\/td>\n<\/tr>\n<tr>\n<td><strong>default-route<\/strong><\/td>\n<td>Static Route<\/td>\n<td><code>0.0.0.0\/0<\/code> via <code>203.0.113.1<\/code><\/td>\n<td>Routes unknown destination traffic to the ISP<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<p>Before configuring Source NAT, ensure the following foundational settings are operational on your firewall:<\/p>\n<ol>\n<li>Layer 3 interfaces (<code>ethernet1\/1<\/code> and <code>ethernet1\/2<\/code>) are configured with correct IP addresses and assigned to their respective zones (<code>Untrust<\/code> and <code>Trust<\/code>).<\/li>\n<li>A Virtual Router is assigned to both interfaces.<\/li>\n<li>A static default route (<code>0.0.0.0\/0<\/code>) exists in the Virtual Router pointing to the ISP gateway IP (<code>203.0.113.1<\/code>).<\/li>\n<li>An Address Object representing the internal subnet (<code>192.168.10.0\/24<\/code>) is created.<\/li>\n<\/ol>\n<h2>Step-by-Step GUI Configuration<\/h2>\n<p>Follow these steps to complete the <strong>Palo Alto Source NAT configuration<\/strong> using the web interface.<\/p>\n<h3>Step 1: Create the Source Network Address Translation Rule<\/h3>\n<ol>\n<li>Log into the PAN-OS web interface.<\/li>\n<li>Navigate to <strong>Policies &gt; NAT<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> at the bottom of the screen to create a new NAT rule.<\/li>\n<\/ol>\n<h3>Step 2: Configure the General Tab<\/h3>\n<ol>\n<li>In the <strong>Name<\/strong> field, enter a clear naming convention, such as <code>snat-outbound-trust-to-untrust<\/code>.<\/li>\n<li>(Optional) Enter a brief description explaining the business purpose of the rule.<\/li>\n<li>Set <strong>NAT Type<\/strong> to <code>ipv4<\/code>.<\/li>\n<\/ol>\n<h3>Step 3: Configure the Original Packet Tab<\/h3>\n<p>The Original Packet tab specifies the criteria for matching incoming traffic <em>before<\/em> any translation occurs.<\/p>\n<ol>\n<li>Click the <strong>Original Packet<\/strong> tab.<\/li>\n<li>Under <strong>Source Zone<\/strong>, click <strong>Add<\/strong> and select <code>Trust<\/code>.<\/li>\n<li>Under <strong>Destination Zone<\/strong>, click <strong>Add<\/strong> and select <code>Untrust<\/code>.<\/li>\n<li>Under <strong>Destination Interface<\/strong>, select <code>ethernet1\/1<\/code> (or leave as <code>Any<\/code>).<\/li>\n<li>Under <strong>Service<\/strong>, keep the default setting of <code>any<\/code>.<\/li>\n<li>Under <strong>Source Address<\/strong>, click <strong>Add<\/strong> and select <code>net-192.168.10.0_24<\/code>.<\/li>\n<li>Under <strong>Destination Address<\/strong>, keep the default setting of <code>any<\/code>.<\/li>\n<\/ol>\n<h3>Step 4: Configure the Translated Packet Tab<\/h3>\n<p>The Translated Packet tab defines how the source or destination address is altered when the rule matches.<\/p>\n<ol>\n<li>Click the <strong>Translated Packet<\/strong> tab.<\/li>\n<li>In the <strong>Source Address Translation<\/strong> section, set <strong>Translation Type<\/strong> to <code>Dynamic IP and Port<\/code>.<\/li>\n<li>Set <strong>Address Type<\/strong> to <code>Interface Address<\/code>.<\/li>\n<li>In the <strong>Interface<\/strong> drop-down menu, select <code>ethernet1\/1<\/code>.<\/li>\n<li>In the <strong>IP Address<\/strong> drop-down menu, select <code>203.0.113.2\/24<\/code>.<\/li>\n<li>Leave <strong>Destination Address Translation<\/strong> set to <code>None<\/code>.<\/li>\n<li>Click <strong>OK<\/strong> to save the NAT rule rule configuration.<\/li>\n<\/ol>\n<h3>Step 5: Verify or Create Security Policy Rule<\/h3>\n<p>NAT policies only permit address translation; they do not allow traffic through the firewall. You must have a Security Policy rule allowing traffic from the <code>Trust<\/code> zone to the <code>Untrust<\/code> zone.<\/p>\n<ol>\n<li>Navigate to <strong>Policies &gt; Security<\/strong>.<\/li>\n<li>Ensure a rule exists allowing traffic from Source Zone <code>Trust<\/code> to Destination Zone <code>Untrust<\/code>.<\/li>\n<li>Confirm the Security Policy uses the <strong>pre-NAT (original)<\/strong> source IP address object (<code>net-192.168.10.0_24<\/code>) and destination IP address (<code>any<\/code>).<\/li>\n<\/ol>\n<h3>Step 6: Commit Configuration<\/h3>\n<ol>\n<li>Click <strong>Commit<\/strong> in the top right corner of the GUI.<\/li>\n<li>Review the change summary and click <strong>Commit<\/strong> again.<\/li>\n<\/ol>\n<h2>CLI Configuration<\/h2>\n<p>For engineers who prefer the Command Line Interface (CLI), perform the following configuration steps from configuration mode. These exact PAN-OS CLI commands build the address object, NAT rule, and security policy.<\/p>\n<pre><code># Enter configuration mode\nconfigure\n\n# Create the address object for the internal LAN segment\nset address net-192.168.10.0_24 ip-netmask 192.168.10.0\/24\n\n# Create the Source NAT rule using Dynamic IP and Port (DIPP)\nset rulebase nat rules snat-outbound-trust-to-untrust from Trust to Untrust source net-192.168.10.0_24 destination any service any dynamic-ip-and-port interface-address interface ethernet1\/1 ip 203.0.113.2\/24\n\n# Create the Security Policy rule allowing outbound internet access\nset rulebase security rules allow-outbound-internet from Trust to Untrust source net-192.168.10.0_24 destination any application any service application-default action allow\n\n# Commit the changes to the active configuration\ncommit\n<\/code><\/button><\/pre>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding PAN-OS packet processing flow is vital for proper policy design and operational troubleshooting. Palo Alto Networks firewalls evaluate security and NAT rules using specific logic.<\/p>\n<ol>\n<li><strong>Ingress Lookup and Route Lookup:<\/strong> An un-translated packet arrives on interface <code>ethernet1\/2<\/code> (Trust zone) with Source IP <code>192.168.10.50<\/code> and Destination IP <code>198.51.100.20<\/code>. The firewall queries the Virtual Router routing table to determine the egress interface (<code>ethernet1\/1<\/code>) and egress zone (<code>Untrust<\/code>).<\/li>\n<li><strong>NAT Policy Match:<\/strong> PAN-OS evaluates NAT rules top-to-bottom. It compares the packet&#8217;s original attributes against configured NAT rules. The match criteria are:\n<ul>\n<li>Source Zone: <code>Trust<\/code><\/li>\n<li>Destination Zone: <code>Untrust<\/code> (determined by the routing lookup in Step 1)<\/li>\n<li>Original Source Address: <code>192.168.10.50<\/code> (matches object <code>net-192.168.10.0_24<\/code>)<\/li>\n<li>Original Destination Address: <code>198.51.100.20<\/code><\/li>\n<\/ul>\n<\/li>\n<li><strong>Security Policy Match:<\/strong> Firewall security policy lookup occurs. Crucially, the firewall evaluates security policies using:\n<ul>\n<li><strong>Original (Pre-NAT) Source IP:<\/strong> <code>192.168.10.50<\/code><\/li>\n<li><strong>Original (Pre-NAT) Destination IP:<\/strong> <code>198.51.100.20<\/code><\/li>\n<li><strong>Post-Routing Destination Zone:<\/strong> <code>Untrust<\/code><\/li>\n<\/ul>\n<\/li>\n<li><strong>Translation Execution:<\/strong> Once the security rule allows the session, the firewall allocates a source translation binding. It rewrites the source IPv4 address from <code>192.168.10.50<\/code> to <code>203.0.113.2<\/code> and assigns a unique source port.<\/li>\n<li><strong>Egress Transmission:<\/strong> The firewall sends the modified packet out interface <code>ethernet1\/1<\/code> across the internet.<\/li>\n<li><strong>Return Traffic Processing:<\/strong> When the external host responds to <code>203.0.113.2<\/code>, the firewall matches the incoming response against its active state table. It translates the destination address back to <code>192.168.10.50<\/code> and routes the frame back to the client host.<\/li>\n<\/ol>\n<h2>Verification<\/h2>\n<p>To verify that the <strong>Palo Alto Source NAT configuration<\/strong> is functioning correctly, perform active connectivity tests and inspect active session state entries.<\/p>\n<h3>1. Client-Side Test<\/h3>\n<p>From an internal workstation (<code>192.168.10.50<\/code>), initiate a web request or ping test to an internet server:<\/p>\n<pre><code># Ping external test IP address\nping 198.51.100.20\n<\/code><\/pre>\n<h3>2. Verify Session via CLI<\/h3>\n<p>Log into the firewall CLI and filter the active session table by internal source IP address:<\/p>\n<pre><code>show session all filter source 192.168.10.50\n<\/code><\/pre>\n<p>Example CLI Output:<\/p>\n<pre>\nID       Application    State   Type Flag  Src[Sport]\/Zone\/Proto (Dst[Dport])\n-------------------------------------------------------------------------------\n12345    icmp           ACTIVE  FLOW       192.168.10.50[4096]\/Trust\/1 (198.51.100.20[0])\n                                           198.51.100.20[0]\/Untrust\/1 (203.0.113.2[4096])\n<\/pre>\n<p>Inspect detailed session information using the session ID:<\/p>\n<pre><code>show session id 12345\n<\/code><\/pre>\n<p>Example Output highlighting Source NAT translation:<\/p>\n<pre>\nSession           : 12345\nC2S flow:\n        source          : 192.168.10.50 [Trust]\n        dst             : 198.51.100.20\n        proto           : 1\n        sport           : 4096          dport           : 0\n        state           : ACTIVE        type            : FLOW\n        src user        : unknown\n        proxy-id        : 0\nS2C flow:\n        source          : 198.51.100.20 [Untrust]\n        dst             : 203.0.113.2\n        proto           : 1\n        sport           : 0             dport           : 4096\n        state           : ACTIVE        type            : FLOW\n        src user        : unknown\n        proxy-id        : 0\nNAT rule                : snat-outbound-trust-to-untrust(vsys1)\nSource NAT              : dynamic-ip-and-port, ip address: 203.0.113.2\n<\/pre>\n<p>The output above confirms that Client-to-Server (C2S) traffic originates from <code>192.168.10.50<\/code>, while Server-to-Client (S2C) return traffic is directed back to the translated address <code>203.0.113.2<\/code>.<\/p>\n<h3>3. Verify Traffic Logs in GUI<\/h3>\n<ol>\n<li>In the firewall web interface, navigate to <strong>Monitor &gt; Logs &gt; Traffic<\/strong>.<\/li>\n<li>Apply the query filter: <code>( src in 192.168.10.50 )<\/code><\/li>\n<li>Verify the column <strong>NAT Source IP<\/strong> displays <code>203.0.113.2<\/code> while <strong>Source IP<\/strong> shows <code>192.168.10.50<\/code>.<\/li>\n<\/ol>\n<h2>Troubleshooting<\/h2>\n<p>If outbound internet connectivity fails after completing the setup, work through these common symptoms and technical checks.<\/p>\n<h3>Symptom 1: Traffic is Dropped by Security Policy<\/h3>\n<ul>\n<li><strong>Likely Cause:<\/strong> A common misconception is configuring the post-NAT address in the Security Policy. Security policy matching uses pre-NAT IP addresses.<\/li>\n<li><strong>Verification Check:<\/strong> Check the traffic logs under <strong>Monitor &gt; Logs &gt; Traffic<\/strong>. Look for log entries showing action <code>drop<\/code> or <code>deny<\/code>. Verify your security rule allows source <code>192.168.10.0\/24<\/code>, destination <code>any<\/code>, and destination zone <code>Untrust<\/code>.<\/li>\n<\/ul>\n<h3>Symptom 2: Traffic Matches Wrong NAT Rule<\/h3>\n<ul>\n<li><strong>Likely Cause:<\/strong> PAN-OS evaluates NAT policies in sequential order from top to bottom. A broader rule positioned higher in the list may match first.<\/li>\n<li><strong>Verification Check:<\/strong> Check the rule order under <strong>Policies &gt; NAT<\/strong>. Ensure specific NAT rules are placed above general overrides. Verify runtime rule execution with:\n<pre><code>test nat-policy-match source 192.168.10.50 destination 198.51.100.20 protocol 6 destination-port 80 dynamic-url no<\/code><\/pre>\n<\/li>\n<\/ul>\n<h3>Symptom 3: NAT Rule Fails to Match Due to Incorrect Destination Zone<\/h3>\n<ul>\n<li><strong>Likely Cause:<\/strong> The Destination Zone in a NAT rule must match the zone associated with the route egress interface for the <em>original, un-translated<\/em> destination IP address.<\/li>\n<li><strong>Verification Check:<\/strong> Confirm routing to the destination IP points out interface <code>ethernet1\/1<\/code> (Untrust zone). Test route lookup:\n<pre><code>test routing fib-lookup ip 198.51.100.20 virtual-router default<\/code><\/pre>\n<\/li>\n<\/ul>\n<h2>Common Mistakes<\/h2>\n<ul>\n<li><strong>Configuring Post-NAT IP Addresses in Security Policy:<\/strong> Always use the original pre-NAT source address (<code>192.168.10.0\/24<\/code>) in the security policy rule. PAN-OS matches security policies before performing source IP rewrite.<\/li>\n<li><strong>Selecting the Wrong Destination Zone in NAT Rules:<\/strong> The destination zone in a NAT rule represents the destination zone of the egress interface determined by routing before translation occurs.<\/li>\n<li><strong>Missing Reverse Route on Next-Hop Router:<\/strong> Ensure the ISP router or upstream gateway knows how to route traffic back to your public IP subnet range.<\/li>\n<li><strong>Confusing Dynamic IP with Dynamic IP and Port:<\/strong> Selecting &#8220;Dynamic IP&#8221; (1-to-1 dynamic mapping without port translation) instead of &#8220;Dynamic IP and Port&#8221; (DIPP) will cause source pool exhaustion if you have more active clients than public addresses.<\/li>\n<\/ul>\n<h2>Production Considerations<\/h2>\n<p>When implementing outbound Source NAT in enterprise environments, account for these operational factors:<\/p>\n<ul>\n<li><strong>DIPP Oversubscription Limits:<\/strong> A single IPv4 address supporting Dynamic IP and Port translation can handle approximately 64,000 concurrent source sessions per destination protocol\/port. For high-density enterprise environments with thousands of users, use a public IP pool (e.g., a <code>\/28<\/code> subnet) in your NAT rule instead of a single interface address.<\/li>\n<li><strong>High Availability Session Synchronization:<\/strong> In Active\/Passive firewall clusters, session state and active NAT bindings sync automatically across HA links. Ensure NAT rules reference zone names rather than static physical interfaces when configuring multi-path HA environments.<\/li>\n<li><strong>Logging at Session End:<\/strong> Ensure <strong>Log at Session End<\/strong> is enabled in your security rules to generate accurate session records showing translated IP addresses and port numbers for regulatory auditing and security incident investigations.<\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>Configuring Source NAT on Palo Alto Networks firewalls translates private internal address spaces to routable public IP addresses for internet access. Key takeaways include:<\/p>\n<ul>\n<li>Use <strong>Dynamic IP and Port (DIPP)<\/strong> translation to map multiple internal client IPs to a single public interface address.<\/li>\n<li>PAN-OS evaluates Security Policies using <strong>pre-NAT source and destination IP addresses<\/strong>, but uses the <strong>post-routing destination zone<\/strong>.<\/li>\n<li>Always verify NAT functionality by combining CLI session checks (<code>show session all filter...<\/code>) with GUI traffic log analysis.<\/li>\n<\/ul>\n<h2>Related Palo Alto Guides<\/h2>\n<ul>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/\">Palo Alto Security Policy Configuration<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-interfaces-zones-configuration\/\">Palo Alto Interfaces and Security Zones<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-virtual-router-default-route\/\">Palo Alto Virtual Router and Default Route<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-destination-nat-configuration\/\">Palo Alto Destination NAT and Port Forwarding<\/a><\/li>\n<\/ul>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What is Source NAT on Palo Alto?<\/h3>\n<p>Source NAT translates an internal source IP address into a routable address so private hosts can establish outbound connections through the firewall.<\/p>\n<h3>Does Palo Alto NAT replace a Security Policy?<\/h3>\n<p>No. A NAT rule performs address translation; a separate Security Policy must allow the traffic.<\/p>\n<h3>Why is DIPP commonly used for internet access?<\/h3>\n<p>Dynamic IP and Port allows many internal clients to share one or more public IP addresses by translating source ports as well as source addresses.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn Palo Alto Source NAT configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.<\/p>","protected":false},"author":2,"featured_media":409,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[5],"tags":[28,29,65,32,66,31],"class_list":["post-410","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-palo","tag-beginner","tag-firewall-tutorial","tag-nat","tag-palo-alto-networks","tag-palo-alto-source-nat-configuration","tag-pan-os"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Palo Alto Source NAT Configuration: Step-by-Step Guide<\/title>\n<meta name=\"description\" content=\"Configure Palo Alto Source NAT with a real-world internet access example, DIPP, security policy, CLI verification and troubleshooting steps.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-source-nat-configuration\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Palo Alto Source NAT Configuration with a Real-Life Internet Access Example\" \/>\n<meta property=\"og:description\" content=\"Configure Palo Alto Source NAT with a real-world internet access example, DIPP, security policy, CLI verification and troubleshooting steps.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-source-nat-configuration\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-09T05:30:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-13T23:10:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-source-nat-configuration-with-a-real-life-internet-access-example-featured.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"Palo Alto Source NAT Configuration with a Real-Life Internet Access Example\",\"datePublished\":\"2026-08-09T05:30:02+00:00\",\"dateModified\":\"2026-09-13T23:10:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/\"},\"wordCount\":1704,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-source-nat-configuration-with-a-real-life-internet-access-example-featured.png\",\"keywords\":[\"Beginner\",\"Firewall Tutorial\",\"NAT\",\"Palo Alto Networks\",\"Palo Alto Source NAT configuration\",\"PAN-OS\"],\"articleSection\":[\"Palo Alto\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/\",\"name\":\"Palo Alto Source NAT Configuration: Step-by-Step Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-source-nat-configuration-with-a-real-life-internet-access-example-featured.png\",\"datePublished\":\"2026-08-09T05:30:02+00:00\",\"dateModified\":\"2026-09-13T23:10:47+00:00\",\"description\":\"Configure Palo Alto Source NAT with a real-world internet access example, DIPP, security policy, CLI verification and troubleshooting steps.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-source-nat-configuration-with-a-real-life-internet-access-example-featured.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-source-nat-configuration-with-a-real-life-internet-access-example-featured.png\",\"width\":1200,\"height\":630,\"caption\":\"Palo Alto Source NAT Configuration with a Real-Life Internet Access Example\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-source-nat-configuration\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Palo Alto Source NAT Configuration with a Real-Life Internet Access Example\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Palo Alto Source NAT Configuration: Step-by-Step Guide","description":"Configure Palo Alto Source NAT with a real-world internet access example, DIPP, security policy, CLI verification and troubleshooting steps.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-source-nat-configuration\/","og_locale":"en_US","og_type":"article","og_title":"Palo Alto Source NAT Configuration with a Real-Life Internet Access Example","og_description":"Configure Palo Alto Source NAT with a real-world internet access example, DIPP, security policy, CLI verification and troubleshooting steps.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-source-nat-configuration\/","og_site_name":"NetworkFix","article_published_time":"2026-08-09T05:30:02+00:00","article_modified_time":"2026-09-13T23:10:47+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-source-nat-configuration-with-a-real-life-internet-access-example-featured.png","type":"image\/png"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"Palo Alto Source NAT Configuration with a Real-Life Internet Access Example","datePublished":"2026-08-09T05:30:02+00:00","dateModified":"2026-09-13T23:10:47+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/"},"wordCount":1704,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-source-nat-configuration-with-a-real-life-internet-access-example-featured.png","keywords":["Beginner","Firewall Tutorial","NAT","Palo Alto Networks","Palo Alto Source NAT configuration","PAN-OS"],"articleSection":["Palo Alto"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/","url":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/","name":"Palo Alto Source NAT Configuration: Step-by-Step Guide","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-source-nat-configuration-with-a-real-life-internet-access-example-featured.png","datePublished":"2026-08-09T05:30:02+00:00","dateModified":"2026-09-13T23:10:47+00:00","description":"Configure Palo Alto Source NAT with a real-world internet access example, DIPP, security policy, CLI verification and troubleshooting steps.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-source-nat-configuration-with-a-real-life-internet-access-example-featured.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-source-nat-configuration-with-a-real-life-internet-access-example-featured.png","width":1200,"height":630,"caption":"Palo Alto Source NAT Configuration with a Real-Life Internet Access Example"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"Palo Alto Source NAT Configuration with a Real-Life Internet Access Example"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/410","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=410"}],"version-history":[{"count":3,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/410\/revisions"}],"predecessor-version":[{"id":1587,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/410\/revisions\/1587"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/409"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=410"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=410"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=410"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}