Forum Discussion
SNAT and NAT precedence
Hi,
In SOL9038 there is sentence "For example, a SNAT with an origin address of 10.10.64.0/24 takes precedence over a SNAT with an origin of default. Additionally, a SNAT with an origin address of 10.10.64.2 takes precedence over a NAT with an origin address of 10.10.64.2."
I did tests (on 11.2.0) and there is no way to create SNAT and NAT object with the same origin IP. Error is displayed when second object is saved with info about origin IP already used.
Is that bug in GUI or error in SOL, or I am missing something important?
Piotr
4 Replies
- StephanManthey
Nacreous
Hi Piotr,
I have no idea, why the documentation discusses the specific subject.
A NAT configuration works bi-directional:
- traffic to the NAT (incoming) will be forwarded to the "Origin" by applying destination address translation
- traffic from the "Origin" (outgoing) will be forwarded to target and source address translation is applied
Where is the use case to combine a SNAT with a NAT?
Whenever possible I avoid to create so called Default SNATs (aka SNAT List entries). Instead I´m using virtual servers to forward traffic and apply SNAT as SNAT AutoMap / SNATpool as property of the virtual server or via iRule.
Thanks, Stephan - dragonflymr
Cirrostratus
Hi,
Well, I have as well no idea why it's presented that way in mentioned SOL. I can't figure out scenario for SNAT-NAT precedence. I was just curious why there is such example when there is no way to create object with same origin IP. I am just learning LTM so sometimes I don't know if it's my lack of knowledge and experience or info in SOL is just plain wrong or my version of TMOS has some bug. Anyway, thanks for reply.
Piotr
- StephanManthey
Nacreous
Hi Piotr, thanks. I agree, there is a couple of ways to handle traffic. Some of them are just there for legacy reasons. And this is confusing, even if one if pretty familiar with the pure technical aspects. Anyway, this is the right place to ask for explanation. :) Thanks, Stephan
- dragonflymr
Cirrostratus
Great there are people having time to answer novice questions like mine!
Piotr
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com