F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices NAT and ALG Configuration Guide-6PW100

Table Of Contents
6
An address pool is a set of consecutive public IP addresses used for dynamic NAT. A NAT gateway
selects addresses from the address pool and uses them as the translated source IP addresses.
To implement NAT for stateful failover (asymmetric-path), you must configure the same address pool on
both devices so that one device can take over when the other device fails. However, if the two devices
select the same IP address from their address pool and assign the same port number, reverse sessions on
the two devices are the same. As a result, they cannot back up session data.
To solve the problem, the low-priority address pool attribute is introduced to NAT. Configure a
non-low-priority address pool on a device and configure a low-priority address pool on the other device.
The two address pools have the same address range, but have different port number ranges so that the
devices can back up session data.
For more information about stateful failover, see High Availability Configuration Guide.
7B
Configuration guidelines
An address pool can contain a maximum of 255 addresses.
On certain types of devices, an address pool cannot include addresses in other address pools, IP
addresses of interfaces with Easy IP enabled, or public addresses of internal servers.
Low-priority address pools cannot include addresses in non low-priority address pools, external IP
addresses for one-to-one NAT, and public addresses of internal servers.
The address pool, dynamic NAT, static NAT, and internal server configurations can be modified
through Web pages. The modification you make takes effect after the former configuration is
removed by the system.
8B
Configuring NAT in the Web interface
45BRecommended configuration procedure
110BConfiguring dynamic NAT
Task Remarks
229H
Creating an address pool Required for NAPT and NO-PAT modes.
230H
Configuring dynamic NAT Required.
111BConfiguring static NAT
Task Remarks
231H
Creating a static address mapping
Required.
Static NAT supports two modes, one-to-one and net-to-net.
232H
Enabling static NAT on an interface Required.