Different Translation Depending on the Destination (Dynamic Manual PAT)
The following figure shows a host on the 10.1.2.0/24 network accessing two different servers. When the host accesses the server at 209.165.201.11, the real address is translated to 209.165.202.129:port. When the host accesses the server at 209.165.200.225, the real address is translated to 209.165.202.130:port.
Before you begin
Ensure that you have interface objects (security zones or interface groups) that contain the interfaces for the device that protects the servers. In this example, we will assume the interface objects are security zones named inside and dmz. To configure interface objects, select , then select Interface.
Procedure
Step 1 | Create a network object for the inside network. |
Step 2 | Create a network object for the DMZ network 1. |
Step 3 | Create a network object for the PAT address for DMZ network 1. |
Step 4 | Create a network object for the DMZ network 2. |
Step 5 | Create a network object for the PAT address for DMZ network 2. |
Step 6 | Configure dynamic manual PAT for DMZ network 1. |
Step 7 | Configure dynamic manual PAT for DMZ network 2. |
Step 8 | Click Save on the NAT rule page. |