How to match 4th octet number in NAT


I want to know how to configure 1 to 1 nat in any ip range.

I want to configure 1-to-1 nat bellow.
e.g.) matching 4th octet number -> -> ->

I configured nat with ip range. (see bellow)

set interfaces dummy dum1 address '' ... set nat source rule 10 outbound-interface 'tun1' set nat source rule 10 source address '' set nat source rule 10 translation address '' ...

I can see a nat translation that matched 4th octet numbers.

$ sh nat source translations Pre-NAT Post-NAT Prot Timeout icmp 11

In this case, is this nat translation always maintained ?



Seems fine to me. If there’s also traffic initiated from other side of the tunnel, add corresponding dNAT rule.


Thank you for your reply.

There are both side traffic.
I have to configure both nat rule (inside-to-outside and outside-to-inside), correct ?
(If only one side, the traffic isn’t be natted?)


You need both destination and source NAT to create full 1:1 NAT.
Normally sNAT is required for initiating outgoing connections (and return traffic is automatically NATted as well)
The dNAT rule is for NATting traffic initiated from outside to inside.