How to set up logs to record nat static?
Not implemented for the static
How to make up for this functional deficiency?
Static NAT is the same as SNAT and DNAT together just in one
You can use them
Since its static you already know which IP is getting translated from/to which gives if you want to log the traffic you can do so on the regular firewall rules that allows this NATed traffic (depending on direction the rule will either be before nating or after nating).
As I recall it the firewall rules will for SNAT act on the new srcip aka after NATing occured (because thats what input/output/forward chains will see) while for DNAT the firewall rules will act on the old dstip (aka before NATing occured).
The flow for this is like: ingress → SNAT (if needed) → firewall rules → DNAT (if needed) → egress
afaik , order is:
ingress → DNAT (if needed) → firewall/routing → SNAT (if needed) → egress
Thank you for your reply. I will give it a try.
Thank you for your reply.