Environment : Any typical environment for the usage of both src-nat and dst-nat functionality
Yes. Dual-nat performs both source and destination NAT on packets matching the rule.Forward packets from source network to destination; re-mark them with destination IP of the target network. This action functions in tunnel/decrypt-tunnel forwarding mode. User should configure the NAT pool in the controller. When using "dual-nat", only the source NAT pool can be specified. However is there a way to dual-nat to external host without the "ip nat inside" option? (Test-Lab) (config-sess-guest-web)#user any tcp 80 dual-nat pool test-pool ?<0-65535> Destination NAT port numberblacklist Blacklist user if ACL gets applieddisable-scanning Pause ARM scanning while traffic is presentdot1p-priority Assign 802.1p prioritylog Log if ACL gets appliedmirror Mirror all session packets to datapath or remote destinationposition Filter position. Default is last. 1 is first.queue Assign queue priority of the flowtime-range Configure time rangetos Set TOS in ip header<cr> Yes; When using "dst-nat" there is an opportunity to specify the destination IP. (Test-Lab) (config-sess-guest-web)#user any tcp 80 dst-nat ?<0-65535> Destination NAT port numberblacklist Blacklist user if ACL gets applieddisable-scanning Pause ARM scanning while traffic is presentdot1p-priority Assign 802.1p priorityip Destination NAT IP addresslog Log if ACL gets appliedmirror Mirror all session packets to datapath or remote destinationposition Filter position. Default is last. 1 is first.queue Assign queue priority of the flowtime-range Configure time rangetos Set TOS in ip header<cr> The destination ip is defined under the nat pool for dual-nat operation: ip NAT pool <pool-name> <start-of-src-pool> <end-of-src-pool> <dst-nat-ip> For example: (Test-Lab) #conf term ip NAT pool arubatest 10.1.1.2 10.1.1.2 172.16.1.1 (Test-Lab) #show ip nat pool NAT Pools---------Name Start IP End IP DNAT IP---- -------- ------ -------Arubatest 10.1.1.2 10.1.1.2 172.16.1.1
© Copyright 2024 Hewlett Packard Enterprise Development LPAll Rights Reserved.