Intra-Zone Source (dynamic) NAT

Reply
Highlighted
L0 Member

Intra-Zone Source (dynamic) NAT

Guest network (10.10.10.0/24) is in Outside zone & Internet link (11.11.11.11/24) is also in same zone.
Guests need to browse internet (say google.com)

My question is about intra-zone source NAT/PAT!

Guest, who is the source of the traffic; requires translation to public IP address (say outside interface of the firewall).
Destination of the traffic is internet i.e. public IP address doesnt need any translation.

Such intra-zone source NAT/PAT is possible? If Yes, How?

Original packet:
Source Zone: Outside
Source Network: Guest network private IP address
Destination Zone: Outside
Destination Network: any
Application: web-browsing
service: http
protocol: tcp

Translated packet:
Source Zone: Outside
Source Network: Guest network public IP address / Firewall outside interface / public IP pool etc.
Destination Zone: Outside
Destination Network:any
Tags (2)
Community Manager

Re: Intra-Zone Source (dynamic) NAT

yes this is perfectly possible

the policy would look nearly identical to a 'normal' nat rule since the operation is identical, but since your source user is in the same zone, the source and destination zone will be identical

this in itself is not a problem but for security i'd recommend putting the users in their own zone (this will give you more control over their connections through security policy)

 

odd nat.png


Help the community: Like helpful comments and mark solutions
Reaper out
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!