Click on the Superior tab. The dynamic NAT All site visitors in this plan and Established supply IP possibilities are picked. The source IP tackle is established to the public IP handle of Mail Server 1, 203. 113. twenty five.
For site visitors dealt with by this plan, dynamic NAT modifications the source IP deal with to the source IP deal with set in the coverage rather than the main IP handle of the external interface. For dynamic NAT to effectively use the resource IP deal with in this policy, the coverage have to meet up with two demands:The policy ought to make it possible for site visitors out by way of only one interface. The dynamic NAT Set resource IP tackle need to be on the same subnet as the IP handle of the interface in the To portion of the coverage.
To verify that this plan meets these needs, click the Plan tab. This policy permits site visitors:From 10. two. twenty five , the private IP handle of Mail Server 1. To Exterior , the title of a certain external interface. This satisfies the initial requirement. The supply IP tackle in this plan (203. 113. http://what-is-my-ip.co 25), is on the exact subnet as the External interface IP handle (203. 113. two). This meets the next requirement. The example configuration also involves a coverage configured to deal with dynamic NAT for outbound visitors for Mail Server 2. To see the plan configuration outbound targeted traffic from Mail Server two:Open the SMTP-out-MS2 coverage.
Click on the Innovative tab to see the Dynamic NAT resource IP tackle configuration. Click on the Plan tab to see the resource and destination of website traffic taken care of by the policy. The supply IP address set in these two guidelines have this result:For outbound targeted visitors from Mail Server one, adjust the supply IP tackle from 10. 2. 25 to 203. 113. 25 For outbound site visitors from Mail Server two, adjust the source IP address from 10. 2. 26 to 203. 113. 26. Summary. The static and dynamic NAT actions and procedures in this configuration work together to tackle deal with translation in the IP packet headers for inbound and outbound site visitors to both equally mail servers. The put together static NAT (SNAT) and dynamic NAT (DNAT) configuration configurations have this result:Traffic way Source IP Tackle Vacation spot IP Deal with NAT Motion Inbound to Exterior 203. 113. 25 SNAT variations desired destination to 10. two. 25 Outbound from Exterior 10. two. 25 DNAT changes supply to 203. 113. twenty five Inbound to Exterior 203. 113. 26 SNAT alterations place to ten. 2. 26 Outbound from External 10. two. 26 DNAT alterations supply to 203. 113. 26. Option two ※ Use one-to-1 NAT. Another strategy to set up NAT for these mail servers is to use 1-to-1 NAT in its place of static and dynamic NAT.
Because one-to-one NAT handles equally incoming and outgoing site visitors, it demands fewer steps to configure one-to-one NAT than it does to configure dynamic and static NAT to the identical servers. The case in point configuration file proven below is nat1-to-1mail. xml . External Interface Configuration. The external interface configuration does not involve two secondary IP addresses. This is unique than the external interface configuration for Choice one. You do not have to have to include secondary exterior interface IP addresses in get to configure them in the one-to-1 NAT settings. Network one-to-one NAT Configuration. Network one-to-one NAT settings apply to visitors taken care of by all procedures in the configuration that have the 1-to-1 NAT check box chosen. The case in point configuration has a solitary 1-to-one NAT rule that handles inbound and outbound NAT for each mail servers.
