End-of-Life (EoL)

Virtual Wire Static NAT Example

In this example, security policies are configured from the virtual wire zone named Trust to the virtual wire zone named Untrust. Host 1.1.1.100 is statically translated to address 2.1.1.100. With the
Bi-directional
option enabled, the firewall generates a NAT policy from the Untrust zone to the Trust zone. Clients on the Untrust zone access the server using the IP address 2.1.1.100, which the firewall translates to 1.1.1.100. Any connections initiated by the server at 1.1.1.100 are translated to source IP address 2.1.1.100.
vwire_nat_static_nat.png
Route on R2:
Destination
Next Hop
2.1.1.100/32
2.1.1.1
vwire_nat_static_screenshot.png

Recommended For You