As shown in Figure-1, the server in the internal network to provide Web services for external users.
Configure the NAT Server feature to allow the external user to use public address 200.2.2.1/24 to access the internal server.
This configuration example was created and verified on R9900P2705 of the F5000-AI-55-G device.
Do not configure both the NAT translation methods and a global NAT policy.
Assign IP addresses to interfaces and add the interfaces to security zones.
# On the top navigation bar, click
# From the navigation pane, select
# Click the
# In the dialog box that opens, configure the interface:
Select the
On the
Click
# Add GE 1/0/2 to the
Configure a security policy.
# On the top navigation bar, click
# From the navigation pane, select
# Click
# In the dialog box that opens, configure policy parameters as follows:
Enter a policy name. In this example, the name is
Select the source zone. In this example, the source zone is Untrust.
Select the destination zone. In this example, the destination zone is Trust.
Select
Select
Specify the IP address of the host as the source IPv4 address. In this example, the address is 100.100.100.100.
Specify the IP address of the server as the destination IPv4 address. In this example, the address is 172.16.100.1.
Click
Configure a NAT server rule.
# On the top navigation bar, click
# From the navigation pane, select
# Click
# Create a NAT server rule, as shown in Figure-2.
Figure-2 Creating a NAT server rule
# Click
Verify that the host can successfully ping the public address.
C:\Users\abc>ping 200.2.2.1
Pinging host.com [200.2.2.1] with 32 bytes of data:
Reply from 200.2.2.1: bytes=32 time<1ms TTL=253
Reply from 200.2.2.1: bytes=32 time<1ms TTL=253
Reply from 200.2.2.1: bytes=32 time<1ms TTL=253
Reply from 200.2.2.1: bytes=32 time<1ms TTL=253
Ping statistics for 200.2.2.1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Verify that a NAT session is generated when the host accesses the internal server.
# On the top navigation bar, click
# From the navigation pane, select
Figure-3 Session list