Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

external-header-nav
keyboard_arrow_up
close
keyboard_arrow_left
Juniper Security Director Cloud User Guide
Table of Contents Expand all
list Table of Contents
file_download PDF
keyboard_arrow_right

Create a NAT Pool

date_range 28-Mar-22

Use the Create NAT Pool page to create NAT pools.

To create a NAT pool:

  1. Select SRX > NAT > NAT Pools.

    The NAT Pools page appears.

  2. Click the add icon (+).

    The Create NAT Pool

  3. Complete the configuration according to the guidelines provided in Table 1.
  4. Click OK to save the changes. A NAT pool is available with the configuration you provided.

    Table 1 provides guidelines on using the fields on the Create NAT Pool page.

    Table 1: Fields on the Create NAT Pool Page

    Field

    Description

    General Information

    Name

    Enter a unique string of alphanumeric characters, dashes, spaces, and underscores. Colons and periods are not allowed. The maximum length is 31 characters.

    Description

    Enter a description string excluding '&', '<', '>' and '\n' characters. The maximum length is 900 characters.

    Pool Type

    Select a NAT pool type to configure:

    • Source

    • Destination

    Pool Address

    Select a NAT pool address or click Add new address to create a NAT pool address.

    Routing Instance

    Devices

    Select the devices to which the NAT pool is applicable.

    Routing Instance

    Select the required routing instance from the list of available routing instances for the selected device.

    Port

    Enter the destination port number that is used for port forwarding. The value of the port can be any value between 1024 to 65535.

    Advanced

    Pool Translation

    Select the translation type for the incoming traffic:

    • No Translation—No translation required for the incoming traffic.

    • Port/Range—Set the global default single port range for source NAT pools with port translation.

    • Overload—Multiple source addresses are translated to pool addresses. If you set Overload as the translation type, the value of the Pool Address field cannot be an IP range or subnet, but it will be a single address.

    Host Address Base

    Enter the base address of the original source IP address range. The Host Address Base is used for IP address shifting.

    Address Pooling

    Select a NAT address pooling behavior:

    • Paired—Use this option for applications that require all sessions associated with one internal IP address to be translated to the same external IP address for multiple sessions.

    • Non-Paired—Use this option for applications that can be assigned IP addresses in a round-robin fashion.

    Port overloading factor

    Enter the port overloading capacity in source NAT. The value can be any value between 2 to 32. If the port-overloading-factor is set to x, each translated IP address will have x number of ports available.

    Address Sharing

    Enable address sharing so that multiple internal IP addresses can be mapped to the same external IP address. Select this option only when the source NAT pool is configured with no port translation. When a source NAT pool has only one or a few external IP addresses available, the address sharing option with a many-to-one address mapping increases NAT resources and improves traffic.

    Port

    Enter the port number for the NAT pools. The value of the port can be any value between 1024 to 65535.

    Start

    Enter the start port value for the source NAT pools. The value of the port range can be any value between 1024 to 65535.

    End

    Enter the end port value for the source NAT pools. The value of the port range can be any value between 1024 to 65535.

    Overflow Pool Type

    Select a source pool to use when the current address pool is exhausted.

    • Interface—Allow the egress interface IP address to support overflow.

    • Pool—Name of the source address pool.

    • Overflow Pool—When addresses from the original source NAT pool are exhausted, IP addresses and port numbers are allocated from the overflow pool. A user-defined source NAT pool or an egress interface can be used as the overflow pool. When the overflow pool is used, the pool ID is returned with the address.

external-footer-nav
Ask AI
close

How can I help you today?

LLMs can make mistakes. Verify important information.
chat_add_on New topic
send progress_activity
This conversation will be monitored and recorded. Any information you provide will be subject to our Privacy Notice and may be used for quality assurance purposes. Do not include any personal or sensitive information. Ask AI can make mistakes. Verify generated output for accuracy.
Protected by hCaptcha arrow_drop_down arrow_drop_up
Juniper Networks, Inc. | Privacy Notice | Terms of Use