NAT Many to One on non Internet interface

EdHayes
Comes here often

NAT Many to One on non Internet interface

I have a requirement for a Vlan (192.16.x.y) on a MX100 to be natted to a private address (10.x.y.z) which exists on an interface on the MX but it's not a Internet interface, it;s an external DMZ interface.  I basically need a many to one NAT function which is not destined for the Internet.  I don't think this is possible with the MX Security Appliance, if it is then I would greatly appreciate some help on this.

 

Would one option be to connect the DMZ to the second WAN Internet Port and configure a private address on it (10.x.y.z) and then would it be possible to do a Many to 1 NAT over this from the internal Vlans ? 

5 Replies 5
PhilipDAth
Kind of a big deal
Kind of a big deal

I think this will work (forget the second WA port).  Try just configuring it.

 

The NAT rules are often processed irrespective of which interface they pass through.

 

For example, you can create a NAT rule for a public IP, but still access the service via that public IP from inside of the network, because the system intercepts the NAT as it flows in through the first interface.

HI Philip,

 

Thanks for your reply.

 

I am trying to NAT out on a DMZ interface which has a private address (10.x.y.z) with overload on that address (PAT), which I cant see how to do that.  The DMZ is effectively just a VLAN assigned to a port on the MX. I cant see a configuration option where it's possible to do a private NAT in the MX other than on a WAN Internet Port.

 

 

PhilipDAth
Kind of a big deal
Kind of a big deal

PAT won't work.  But you should be able to configure 1:many and 1:1 on any interface and have it work.  1:1 should definitely work.

Thanks for the reply. If I try to configure a 1:Many NAT or a 1:1 Nat the uplink option is either Internet 1 or Internet 2, are you saying that this would be not relevant if specified the address of the DMZ ? Also is it possible to use a Pool of IP addresses for the destination NAT ?

 

 

EdHayes
Comes here often

Any update on this question please as I still don't have an answer to what I'm trying to achieve .... Any more info or guidance would be much appreciated ...

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels