Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

Configuring Static Destination NAT for Next Gen Services

date_range 06-Dec-23

Configuring the Destination Pool for Static Destination NAT

To configure the destination pool for static destination NAT:

  1. Create a destination pool.
    content_copy zoom_out_map
    user@host# edit services nat destination pool nat-pool-name
    
  2. Define the addresses or subnets to which destination addresses are translated.
    content_copy zoom_out_map
    [edit services nat destination pool nat-pool-name]
    user@host# set address address-prefix
    
  3. To allow the IP addresses of a NAT destination pool to overlap with IP addresses in pools used in other service sets, configure allow-overlapping-pools.
    content_copy zoom_out_map
    [edit services nat]
    user@host# set allow-overlapping-pools
    

Configuring the NAT Rule for Static Destination NAT

To configure the NAT rule for static destination NAT:

  1. Configure the NAT rule name.
    content_copy zoom_out_map
     [edit services nat destination]
    user@host# set rule-set rule-set-name rule rule-name
    
  2. Specify the traffic direction to which the destination NAT rule set applies.
    content_copy zoom_out_map
     [edit services nat destination rule-set rule-set-name]
    user@host# set match-direction (in | out | in-out)
    
  3. Specify the source addresses of traffic that the NAT rule applies to.

    To specify one address or prefix value:

    content_copy zoom_out_map
     [edit services nat destination rule-set rule-set-name rule rule-name]
    user@host# set match source-address address
    

    To specify a range of addresses, configure an address book global address with the desired address range, and assign the global address to the NAT rule:

    content_copy zoom_out_map
     [edit services address-book global]
    user@host# set address address-name range-address lower-limit to upper-limit
     [edit services nat destination rule-set rule-set-name rule rule-name]
    user@host# set match source-address-name address-name
    

    To specify any unicast address:

    content_copy zoom_out_map
     [edit services nat destination rule-set rule-set-name rule rule-name]
    user@host# set match source-address any-unicast
    
  4. Specify the destination addresses that the NAT rule applies to.
    content_copy zoom_out_map
     [edit services nat destination rule-set rule-set-name rule rule-name]
    user@host# set match destination-address address
    

    To specify a range of addresses, configure an address book global address with the desired address range, and assign the global address to the NAT rule:

    content_copy zoom_out_map
     [edit services address-book global]
    user@host# set address address-name range-address lower-limit to upper-limit
     [edit services nat destination rule-set rule-set-name rule rule-name]
    user@host# set match destination-address-name address-name
    

    To specify any unicast address:

    content_copy zoom_out_map
     [edit services nat destination rule-set rule-set-name rule rule-name]
    user@host# set match destination-address any-unicast
    
  5. Specify one or more application protocols to which the destination NAT rule applies. The number of applications listed in the rule must not exceed 3072.
    content_copy zoom_out_map
     [edit services nat source rule-set rule-set-name rule rule-name]
    user@host# set match application [application-name]
    
  6. Specify the NAT pool that contains the destination addresses for translated traffic.
    content_copy zoom_out_map
     [edit services nat destination rule-set rule-set-name rule rule-name]
    user@host# set then destination-nat pool nat-pool-name
    
  7. Configure the generation of a syslog when traffic matches the destination NAT rule match conditions.
    content_copy zoom_out_map
     [edit services nat destination rule-set rule-set-name rule rule-name then]
    user@host# set syslog
    

Configuring the Service Set for Static Destination NAT

To configure the service set for static destination NAT:

  1. Define the service set.
    content_copy zoom_out_map
     [edit services]
    user@host# edit service-set service-set-name
    
  2. Configure either an interface service, which requires a single service interface, or a next-hop service, which requires an inside and outside service interface.
    content_copy zoom_out_map
     [edit services service-set service-set-name]
    user@host# set interface-service service-interface interface-name
    

    or

    content_copy zoom_out_map
     [edit services service-set service-set-name]
    user@host# set next-hop-service inside-service-interface interface-name outside-service-interface interface-name
    
  3. Specify the NAT rule sets to be used with the service set.
    content_copy zoom_out_map
     [edit services service-set service-set-name]
    user@host# set nat-rule-sets rule-set-name
    
footer-navigation