- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
11-20-2018 03:30 PM
Hi all,
I'm trying to create Nat rule for source translate when the source is address group and it will not be bi-directional.
The address group include 2 address from objects.
The source translate is Static-IP tried to put object and specifric IP address with subnet (/32)
I keep receiving the following error, also tried to use two-source address instead of address group with success.
I'm on PANOS 8.1.1
11-21-2018 07:57 AM
In this case you can't use static-ip.
Choose "Dynamic IP And Port" from droppdown.
11-20-2018 07:11 PM - edited 11-20-2018 07:12 PM
If you have more than 1 IPs on one side then you have to have same amount at other side to use static nat.
Static nat leaves port number the same so if source sends traffic out from port 1234 then after static nat source port is still 1234.
In case of Dynamic IP And Port option source port is changed so multiple source IPs can be behind one IP.
In your case you have to use Dynamic IP And Port option.
11-21-2018 01:09 AM
This will work (bi-directional static nat for a bunch of ip addresses) only if you set your original source addresses to a subnet (not a group object) and the subnet mask needs to exactly match the translation subnet
11-21-2018 07:34 AM - edited 11-21-2018 07:36 AM
@reaper@Raido_Rattameisterthank you for the reply,
My goal here is to create Nat rule for two internal servers that go out using the same external IP,
Only for outbound direction no bi-directional.
I tried to use their IP address /32 and also for the static IP /32 without success.
11-21-2018 07:57 AM
In this case you can't use static-ip.
Choose "Dynamic IP And Port" from droppdown.
11-21-2018 08:03 AM
@Raido_Rattameister, for the dynamic IP and port it allows my to apply that Nat rule.
How it will behave if those servers are exhcnage servers in DAG design and the outbound traffic is 25 SMTP.
Does the smtp traffic will work on the other end? sending emails out?
11-21-2018 09:29 AM
Email systems really don't care about the source-port the traffic is coming from; the traffic just need to hit and open port on the other end.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!