The configuration method to realize NAT and policy-route for the underlying user

Latest reply: Mar 25, 2016 23:15:42 967 1 0 0

The networking structure: refer to the appendix
the networking requirement
: NE40 connects with two private network segments, one is user, which is out from the interface via NE40 which connects with ISP A, if the link is down, it is out from the interface connecting with ISP B, the other is, it is out from the interface connecting with ISP B, if the link is down, it is out from the interface connecting with ISP A, the users of those two private network segments realize NAT on NE40.

Data deployment
: corresponds to the NAT address pool " to", corresponds to the NAT address pool " to", the IP of NE40 connecting with ISP A is, the IP of NE40 connecting with ISP B is


  • x
  • convention:

Adamcolob Created Mar 25, 2016 23:15:42 Helpful(0) Helpful(0)

Handling Process

The followings are the configuration cases
configure one flow classification rule based on IP
rule-map intervlan rule1 ip any                         
rule-map intervlan rule2 ip any

confiugre the NAT address pool
nat address-group liantong mask slot 5                                                                       
nat address-group yidong mask slot 5

configure NAT policy
nat-policy number 1 ip nat address-group liantong                
nat-policy number 2 ip nat address-group yidong

confiugre NAT policy action                                                    
flow-action liantong nat 1 2
flow-action yidong nat 2 1

configure EACL
associate the flow classification and NAT policy action
eacl nat rule1 liantong
eacl nat rule2 yidong

on the in-interface, enable eacl
interface ethernet 1/0/0
access-group router eacl nat

ip route-static preference 60
ip route-static preference 100                   
ip route-static NULL 0 preference 60             
ip route-static NULL 0 preference 60

Root Cause
The above version of VRP3.10-2222SP01 supports NAT switch and policy route realization simultaneously.

  • x
  • convention:


You need to log in to reply to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!

Login and enjoy all the member benefits

Fast reply Scroll to top