@mo_unify , the only way to do it with the NAT method is to enter every single IP address for the entire subnet... which isn't practical. If you need an entire subnet opened then the best approach will be to log a ticket with support to get the Company 2 MX network enabled for No-NAT. When this has been done you can specify that NAT is not to be used on a specific WAN port, or a specific VLAN on a specific WAN port. Just be aware that when No-NAT support is enabled it also enables the inbound firewall rules for independent configuration (so no longer tied to the NAT translations), but by default it allows everything inbound (generally not desirable) so you need to start by fixing that. Once No-NAT is enabled, you can turn off NAT for the 10.0.99.0/24 VLAN, and then after adding a 'deny any any' rule to the inbound firewall you can then fine tune your rules to what you actually want.
... View more