Configuring dynamic nat – H3C Technologies H3C SecPath F1000-E User Manual
Page 15
8
Item Description
End IP Address
Specify the end IP address of the address pool.
The end IP address must be identical to or higher than the start IP address.
Low priority
Configure the address pool as a low-priority or a non low-priority address pool.
IMPORTANT:
This configuration item is applicable to the stateful failover networking only. You cannot
configure the same address pool as the low-priority address pool on the local and peer
devices.
Configuring dynamic NAT
NOTE:
If Easy IP is configured on an interface or the public IP address is the same as the IP address of the
interface, address translation cannot be associated with any VRRP group.
Select Firewall > NAT Policy > Dynamic NAT from the navigation tree to enter the page shown in
. In the Dynamic NAT field where all dynamic NAT policies are displayed, click Add to enter the Add
Dynamic NAT page shown in
.
Figure 7 Adding dynamic NAT
Table 5 Configuration items
Item Description
Interface
Specify an interface on which dynamic NAT is to be enabled.
ACL
Specify an ACL for dynamic NAT.
You cannot associate an ACL with multiple NAT address pools, or associate an ACL
with both Easy IP and an address pool.
IMPORTANT:
On some devices, the rules of an ACL applied on an interface cannot conflict with one
another, that is, rules with the same source IP address, destination IP address, and VPN
instance are considered as a conflict. In a basic ACL (numbering 2000 to 2999), rules
with the same source IP address and VPN instance are considered as a conflict.