Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

SNAT do I need to add the SNAT address to my lo

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

SNAT do I need to add the SNAT address to my lo

L4 Transporter

Hi

 

I have a working SNAT, but the src nat address is only defined in the SNAT rule.  should I also add it to a lo 

 

Alex

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

Could you expand you your question and add additional information please?

 

Regards,

OKay 

 

A/P cluster

Internet IF - 1.2.3.4/24

Internal IF - 192.168.1.1/24

 

S NAT  rule src Internal going to internet SNAT to 1.2.3.13/32

 

Now I don't have 1.2.3.13/32 allocated to any interface. But the PA's know to do proxy arp for it.

 

As best practise should I allocate the IP as a secondary ip to Internet IF or to a loopback or just leave it un allocated.

 

The only issue with unallocated is I can't ping it!

 

Will there be a problem is I allocated it to a Lo

Hello,

Hopefully I am on the right track here, please correct me if I am not. The IP's from your ISP are 1.2.3.4/24 and as long as they are routing them to your PAN, you shouldnt need an external IP. With respect to the not responding to pings, thats not all bad since you become more 'invisible' from the internet. I actually preferr it this way but there are reasons to be discoverable.

 

Hope that helps.

  • 1772 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!