L3 Switch NAT Breakout
Network Address Translation(NAT), our implement is more like Port Address Translation(PAT), but I think call it Flow Address Translation(FAT) might be better.
Config XML
<configSet reboot="no">
<args>
<nat>true</nat>
</args>
</configSet>ARRAY NTB XML
breakout dns (basic sample)
<run>
<filter id="99" alt="dns query" sessionBase="no">
<or>
<find name="udp.port" relation="==" content="53"/>
</or>
</filter>
<filter id="3" sessionBase="no">
<or>
<find name="arp.request.target.ip" relation="==" content="172.16.10.10"/>
</or>
</filter>
<output id="3">
<port>P5</port>
<arp_reply_default_mac/>
</output>
<output id="5">
<port>P5</port>
<modify_src_default_mac/>
<modify_srcip nat="yes">172.16.10.10</modify_srcip>
<gateway>172.16.10.1</gateway>
</output>
<output id="6" arp_dstip_mac="yes">
<port>P6</port>
</output>
<chain>
<in>P6</in>
<fid type="and">F99</fid>
<out>O5</out>
<next type="notmatch">
<out>P7</out>
</next>
</chain>
<chain>
<in>P7</in>
<out>P6</out>
</chain>
<chain>
<in>P5</in>
<fid>F3</fid>
<out>O3</out>
<next type="notmatch">
<out>O6</out>
</next>
</chain>
</run>breakout dns and replace dns query server
breakout ssh and reply ICMP fragmentation needed if packet length over 1500
Last updated