beautypg.com

Configuring dynamic nat – H3C Technologies H3C SecPath F1000-E User Manual

Page 15

background image

8

Item Description

End IP Address

Specify the end IP address of the address pool.
The end IP address must be identical to or higher than the start IP address.

Low priority

Configure the address pool as a low-priority or a non low-priority address pool.

IMPORTANT:

This configuration item is applicable to the stateful failover networking only. You cannot

configure the same address pool as the low-priority address pool on the local and peer

devices.

Configuring dynamic NAT

NOTE:

If Easy IP is configured on an interface or the public IP address is the same as the IP address of the
interface, address translation cannot be associated with any VRRP group.

Select Firewall > NAT Policy > Dynamic NAT from the navigation tree to enter the page shown in

Figure

5

. In the Dynamic NAT field where all dynamic NAT policies are displayed, click Add to enter the Add

Dynamic NAT page shown in

Figure 7

.

Figure 7 Adding dynamic NAT

Table 5 Configuration items

Item Description

Interface

Specify an interface on which dynamic NAT is to be enabled.

ACL

Specify an ACL for dynamic NAT.
You cannot associate an ACL with multiple NAT address pools, or associate an ACL
with both Easy IP and an address pool.

IMPORTANT:

On some devices, the rules of an ACL applied on an interface cannot conflict with one

another, that is, rules with the same source IP address, destination IP address, and VPN

instance are considered as a conflict. In a basic ACL (numbering 2000 to 2999), rules
with the same source IP address and VPN instance are considered as a conflict.