I will also take a closer look at this Nikolay. I'll keep you posted.
Original Message:
Sent: 06-13-2024 11:06
From: Nikolay Semov
Subject: How to do destination NAT with domain?
I don't have a box running 22 to test with, but I saw this in a recently-updated KB, except in their example they're using it to match the source-address rather than the destination-address.
https://supportportal.juniper.net/s/article/SRX-DNS-name-is-not-a-supported-address-or-address-set-type-in-NAT-rules?language=en_US
So close to your use case ... Maybe next time ...
------------------------------
Nikolay Semov
Original Message:
Sent: 06-13-2024 05:20
From: vidar.stokke
Subject: How to do destination NAT with domain?
Thanks Nikolay.
As far as I can see and with the tests I've done, this does not resolve my problem.
My use case for this is doing source-NAT to a specific source pool when traffic has a destination which is a FQDN. I am unable to create a NAT rule with a match on destination-address that is a address book entry of the type "DNS Host". It seems that the fix you linked to, is the support for using FQDN in a NAT pool.
------------------------------
Best regards
Vidar Stokke
Original Message:
Sent: 06-11-2024 16:06
From: Nikolay Semov
Subject: How to do destination NAT with domain?
Correction: DNS for NAT is supported starting in 22.2R1.
https://www.juniper.net/documentation/us/en/software/junos/release-notes/22.2/junos-release-notes-22.2r1/topics/new-features/feature-descriptions/nat-7.html
Address entries should be defined in the global address book.
------------------------------
Nikolay Semov
Original Message:
Sent: 05-16-2024 09:33
From: vidar.stokke
Subject: How to do destination NAT with domain?
Ahh... actually a nice suggestion to use scripts. Maybe using automation scripting that does a DNS lookup and updates a address-book entry regularly?
------------------------------
Best regards
Vidar Stokke
Original Message:
Sent: 05-14-2024 11:39
From: Nikolay Semov
Subject: How to do destination NAT with domain?
I suspect there are chip features that do NAT in hardware. I doubt they'll ever tie those rigid rules to something dynamic like DNS resolution.
But ... perhaps commit script macros? (https://www.juniper.net/documentation/us/en/software/junos/automation-scripting/topics/concept/junos-software-automation-commit-script-macros.html) Or maybe some other scripting magic...
------------------------------
Nikolay Semov
Original Message:
Sent: 05-13-2024 04:33
From: vidar.stokke
Subject: How to do destination NAT with domain?
Hi.
8 years later... I guess this is still not solved in JunOS?
Does anyone have a good workaround?
------------------------------
Best regards
Vidar Stokke
Original Message:
Sent: 06-06-2016 22:41
From: joses
Subject: How to do destination NAT with domain?
Hello ,
DNS name in NAT rule is not supported . Please check :
http://kb.juniper.net/InfoCenter/index?page=content&id=KB27679&actp=RSS