Intra-Zone Source (dynamic) NAT

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Intra-Zone Source (dynamic) NAT

L0 Member
Guest network (10.10.10.0/24) is in Outside zone & Internet link (11.11.11.11/24) is also in same zone.
Guests need to browse internet (say google.com)

My question is about intra-zone source NAT/PAT!

Guest, who is the source of the traffic; requires translation to public IP address (say outside interface of the firewall).
Destination of the traffic is internet i.e. public IP address doesnt need any translation.

Such intra-zone source NAT/PAT is possible? If Yes, How?

Original packet:
Source Zone: Outside
Source Network: Guest network private IP address
Destination Zone: Outside
Destination Network: any
Application: web-browsing
service: http
protocol: tcp

Translated packet:
Source Zone: Outside
Source Network: Guest network public IP address / Firewall outside interface / public IP pool etc.
Destination Zone: Outside
Destination Network:any
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

yes this is perfectly possible

the policy would look nearly identical to a 'normal' nat rule since the operation is identical, but since your source user is in the same zone, the source and destination zone will be identical

this in itself is not a problem but for security i'd recommend putting the users in their own zone (this will give you more control over their connections through security policy)

 

odd nat.png

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

yes this is perfectly possible

the policy would look nearly identical to a 'normal' nat rule since the operation is identical, but since your source user is in the same zone, the source and destination zone will be identical

this in itself is not a problem but for security i'd recommend putting the users in their own zone (this will give you more control over their connections through security policy)

 

odd nat.png

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 2790 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!