Got it

[Dr.wow]Q&A: Can Interface IP Addresses Be Used for NAT Server or Source NAT Policy Translation on the Firewall?

Latest reply: Mar 29, 2021 14:02:02 312 2 2 0 0

Yes. You can use an interface IP address for NAT Server or Source NAT Policy Translation.

  • If the global IP address of the NAT server uses the interface IP address: When packets access the firewall, the firewall translates the destination IP address of the packet first. The IP addresses of packets accessing the interface are always replaced with the inside IP address of NAT Server. As a result, the interface cannot be accessed. Some common operations such as ping detection, web management, and Telnet management on the interface may cause problems. Therefore, do not use the interface IP address as the global IP address of NAT Server. Instead, you can use the protocol-based NAT Server in the case that protocols do not conflict with each other.

  • If the interface IP address is used as the source NAT policy, when the packet proactively accesses the interface IP address of the firewall, the packet goes through the first-packet procedure and can directly access the interface IP address without being affected by the source NAT policy configuration.

    Notice:

    When nat sever and nat outbound are configured together, the priority of the nat server is higher than that of the nat outbound. That is, packets match the nat server first.

     

     

IndianKid
Moderator Author Created Mar 29, 2021 11:28:11

Very Useful. thanks
View more
  • x
  • convention:

Good sharing
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.