NAT rules specify which traffic is directed to the Server Pool. You can use NAT rules to apply both source and destination address translation for Server Pools.
Before you begin
Add Access rules that allow the type of traffic that is handled by the Server Pool.
If there are any existing Access rules that enable Server Pool load balancing, we recommend that you remove the Server Pool elements from the rules or delete the rules before you
configure NAT rules for Server Pool load balancing.
Note: If the Destination cell of an Access rule contains a Server Pool element, the
Access rule applies Server Pool load balancing, and the NAT rules are ignored.
When you use destination address translation with Server Pools, the NAT operation translates the external IP addresses of Server Pool elements to the internal IP addresses of the Host
elements that are members of the Server Pool.
When using source address translation with Server Pools, return packets from the Server Pool servers are routed through the Engine to the client and recognized as part of the existing
connection. This feature also enables dynamic source NAT with Server Pool load balancing.
Note the following:
- Make sure that there are no overlapping NAT rules in the policy.
- If you want to balance traffic that arrives through a VPN using a Server Pool, NAT must be enabled in the properties of the VPN element (NAT is disabled by default for traffic
that uses a VPN).
- You must create a separate NAT rule for each Server Pool.
Steps
-
Open the Engine Policy for editing and add an IPv4 or IPv6 NAT rule.
Note: If the Server Pool uses both IPv4 and IPv6 addresses, you must create separate IPv4 and IPv6 NAT rules.
-
Add the elements that represent the IP addresses of the clients that connect to the Server Pool to the Source cell.
-
Add the Server Pool element to the Destination cell.
The Server Pool element must be the only element in the Destination cell. Destination address translation is automatically configured when you add a Server Pool element to the
Destination cell. You cannot change the destination translation options.
-
Add the Service element that represents the service that the Server Pool offers to the Service cell.
Note: Each rule must contain only one service.
-
(Optional) Double-click the NAT cell, then define options for source address translation.
Defining source address translation routes return packets from servers in the Server Pool to the clients through the Engine.
-
Save and Install the Engine Policy to transfer the changes.
Next steps
If you want the Engine to automatically update dynamic DNS (DDNS) entries for the Server Pool according to the available NetLinks,
configure DDNS updates.