sk105302 - Traffic NATed behind an Address Range object is always NATed behind the same IP address

Traffic NATed behind an Address Range object is always NATed behind the same IP address

Product Cluster - 3rd-party, ClusterXL, Security Gateways, VSX (Traditional)
Version R80.20SP (EOS), R80.30 (EOS), R80.30SP (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS Gaia
Last Modified 2025-09-11

Symptoms

Cause

When using Manual Hide NAT to hide one or more networks behind the Security Gateway, it is possible to hide the traffic behind an Address Range object instead of a single IP address. This may be desired if a high amount of traffic is expected from the network being NATed because it is only possible to NAT around 50,000 connections behind one IP address.

When traffic is NATed behind an Address Range object, the algorithm used to calculate which IP address is used is based on the original Source IP address. If all traffic tests are performed using the same Source IP address, then the translated source IP address will always be the same as well.

Solution

We're here for you

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level Advanced
Status Approved by TAC
Date Created 2015-04-16
Last Modified 2025-09-11