Expand all | Collapse all

source + destination NAT vs static NAT

  • 1.  source + destination NAT vs static NAT

    Posted 07-28-2017 20:40

    Hi all, 

    I want to open the topic compare with source + destination NAT vs static NAT. 
    Like you know:
    - Source NAT supports internal IP access to the Internet and is one-way direction
    - Destination NAT supports access internal IP through IP public from the Internet and is also unidirectional connection.

    - Static NAT is known 1-1 mapping.
    So what happens when deploying source + destination NAT instead of using static NAT. 

    I have a topology: 

    PC: ------------ SRX  ge0/0/0: the Internet. 

    Destination NAT: to; source NAT pool is also or use source NAT interface

    if I use static NAT, the traffic flow like below
    IN: ->
    OUT ->
    Reverse static
    IN: ->
    OUT ->

    and when I use source + destination NAT
    The non-reverse static is approximate 
    IN: -> 
    OUT: -> 
    The resverse statis is approximate 
    IN: ->
    OUT ->

    So I think source + destination NAT is okay to deploy bi-directional connection. In a nutshell, what's the root cause to use static NAT? Please clarify for me to truly understand. 

    Hoang Nguyen Huy


  • 2.  RE: source + destination NAT vs static NAT

    Posted 07-29-2017 03:06

    You can use the combination of source and destination NAT and have the same effect as Static NAT.


    Static NAT is simply a short cut that allows you to do the both directions NAT all in one configuration.  You can use whichever you prefer.