Can't create Nat rule using more than one source address

Reply
L3 Networker

Can't create Nat rule using more than one source address

Hi all,

 

I'm trying to create Nat rule for source translate when the source is address group and it will not be bi-directional.

 

The address group include 2 address from objects.

The source translate is Static-IP tried to put object and specifric IP address with subnet (/32)

 

I keep receiving the following error, also tried to use two-source address instead of address group with success.

 

I'm on PANOS 8.1.1

 

Nat rule error.jpg

L7 Applicator

Re: Can't create Nat rule using more than one source address

If you have  more than 1 IPs on one side then  you have to have same amount at other side to use static nat.

Static nat leaves port number the same so if source sends traffic out from port 1234 then after static nat source port is still 1234.

In case of Dynamic IP And Port option source port is changed so multiple source IPs can be behind one IP.

 

In your case you have to use Dynamic IP And Port option.

Enterprise Architect @ Cloud Carib www.cloudcarib.com
ACE (3.0, 5.0, 6.0, 7.0), PCNSE (6, 7), PCNSI
Community Manager

Re: Can't create Nat rule using more than one source address

This will work (bi-directional static nat for a bunch of ip addresses) only if you set your original source addresses to a subnet (not a group object) and the subnet mask needs to exactly match the translation subnet

 

bidir static subnet.png


Help the community: Like helpful comments and mark solutions
Reaper out
L3 Networker

Re: Can't create Nat rule using more than one source address

@reaper@Raidothank you for the reply,

 

My goal here is to create Nat rule for two internal servers that go out using the same external IP,

 

Only for outbound direction no bi-directional.

 

I tried to use their IP address /32 and also for the static IP /32 without success.nat rule fail.jpg

 

 

L7 Applicator

Re: Can't create Nat rule using more than one source address

In this case you can't use static-ip.

Choose "Dynamic IP And Port" from droppdown.

Enterprise Architect @ Cloud Carib www.cloudcarib.com
ACE (3.0, 5.0, 6.0, 7.0), PCNSE (6, 7), PCNSI
L3 Networker

Re: Can't create Nat rule using more than one source address

@Raido, for the dynamic IP and port it allows my to apply that Nat rule.

 

How it will behave if those servers are exhcnage servers in DAG design and the outbound traffic is 25 SMTP.

 

Does the smtp traffic will work on the other end? sending emails out?

 

 

L7 Applicator

Re: Can't create Nat rule using more than one source address

@SShnap,

Email systems really don't care about the source-port the traffic is coming from; the traffic just need to hit and open port on the other end. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!