Knowledge Center Search




 

SRX Getting Started - Configure NAT (Network Address Translation)

  [KB15758] Show KB Properties

  [KB15758] Hide KB Properties

Categories:
Knowledge Base ID: KB15758
Last Updated: 25 Apr 2012
Version: 4.0

Summary:

This article identifies resources for configuring, verifying and troubleshooting Network Address Translation (NAT) on SRX Series devices.

For other topics, go to the SRX Getting Started main page.

Problem or Goal:

Configure NAT:  Source NAT, Destination NAT, and Static NAT.

Cause:

Solution:

This section contains the following:


Configuration

In addition to the technical documentation, the following three technote documents have NAT configuration examples:
TIPS:
  • An understanding of the NAT rule-set evaluation priority is important for configuring NAT.  If a packet matches multiple rule-sets, the most specific match takes precedence.  The order of precedence is as follows (first destination, then source):
    • Interface
    • Zone
    • Routing-Instance
    Refer to the 'New Design and Processing' section of TN8 for diagrams of the flow and more information.

  • Although, the title of TN25 refers to ScreenOS users, the examples in the technote are benefical to non-ScreenOS users too. 

Technical Documentation

JUNOS Security Configuration Guide

  • PDF - See Chapter 42, Network Address Translation (page 1199)
  • HTML - Network Address Translation

Verification

The following commands are helpful for verifying and troubleshooting NAT:
show security nat source summary
show security nat source rule
show security nat source pool
show security nat destination summary
show security nat destination pool
show security nat destination rule
show security nat static rule
show security flow session
HTML - Verifying Network Address Translation

Troubleshooting

KB21922 - Resolution Guides and Articles - SRX - NAT

KB16252 - Troubleshooting NAT in SRX series



Purpose:
Configuration

Related Links:

 

 

ASK THE KB

Question or KB ID:


 


 

 
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.