Learn how to configure separate source NAT IP addess pools for active/active HA
firewalls.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Strata Cloud Manager)
- NGFW (Managed by PAN-OS or Panorama)
|
For Strata Cloud Manager managed NGFWs:
|
If you want to use IP address pools for source
NAT in Active/Active HA, each firewall must have its own
pool, which you then bind to a Device ID in a NAT rule.
Address objects and NAT rules are synchronized
(in both active/passive and active/active mode), so they need to
be configured on only one of the firewalls in the HA pair.
This
example configures an address object named Dyn-IP-Pool-dev0 containing
the IP address pool 10.1.1.140-10.1.1.150. It also configures an
address object named Dyn-IP-Pool-dev1 containing the IP address
pool 10.1.1.160-10.1.1.170. The first address object is bound to
Device ID 0; the second address object is bound to Device ID 1.