Hello, Alex!
I tried / 29, but it seems to me now the problem in return traffic
Rule/ Trasnlation is works.
but
{master}
admin@M10_MX480> show services stateful-firewall flows extensive | match 8.8.8.8
ICMP 192.168.72.145 -> 8.8.8.8 Forward I 179
ICMP 8.8.8.8 -> 185.13.112.252 Forward O 0
{master}
admin@M10_MX480>
{master}
admin@M10_MX480> show services stateful-firewall flows | match 8.8.8.8
UDP 192.168.72.144:61984 -> 8.8.8.8:53 Forward I 5
UDP 8.8.8.8:53 -> 185.13.112.253:41663 Forward O 0
UDP 192.168.72.144:64695 -> 8.8.8.8:53 Forward I 5
UDP 8.8.8.8:53 -> 185.13.112.253:22013 Forward O 0
ICMP 192.168.72.144 -> 8.8.8.8 Forward I 87
ICMP 8.8.8.8 -> 185.13.112.253 Forward O 0
{master}
admin@M10_MX480>
{master}
admin@M10_MX480> show route table inet.0 185.13.112.253 extensive
inet.0: 541141 destinations, 924298 routes (540938 active, 0 holddown, 620 hidden)
185.13.112.253/32 (1 entry, 1 announced)
TSI:
KRT in-kernel 185.13.112.253/32 -> {Service}
Aggregated into 185.13.112.0/22
*Static Preference: 1
Next hop type: Service
Address: 0x16568224
Next-hop reference count: 12
Next hop:
Next-hop service: AMS
Next-hop index: 620
State: <Active Int ProxyArp>
Age: 5:22
Validation State: unverified
Task: RPD Unix Domain Server./var/run/rpd_serv.local
Announcement bits (3): 0-KRT 5-Resolve tree 2 7-Aggregate
AS path: I
{master}
admin@M10_MX480> show route table inet.0 185.13.112.162 extensive
inet.0: 541141 destinations, 924298 routes (540938 active, 0 holddown, 620 hidden)
185.13.112.160/29 (1 entry, 1 announced)
TSI:
KRT in-kernel 185.13.112.160/29 -> {Service}
Aggregated into 185.13.112.0/22
*Static Preference: 1
Next hop type: Service
Address: 0x16568224
Next-hop reference count: 12
Next hop:
Next-hop service: AMS
Next-hop index: 620
State: <Active Int ProxyArp>
Age: 5:23
Validation State: unverified
Task: RPD Unix Domain Server./var/run/rpd_serv.local
Announcement bits (3): 0-KRT 5-Resolve tree 2 7-Aggregate
AS path: I
{master}
admin@M10_MX480>
{master}
admin@M10_MX480> show configuration services
service-set AMS {
nat-rules AMS;
next-hop-service {
inside-service-interface ams0.10;
outside-service-interface ams0.20;
}
}
nat {
pool OFFICE {
address-range low 185.13.112.160 high 185.13.112.191;
port {
automatic {
random-allocation;
}
}
address-allocation round-robin;
}
pool TEST_PBA {
address-range low 185.13.112.192 high 185.13.112.200;
port {
automatic {
random-allocation;
}
secured-port-block-allocation block-size 64 max-blocks-per-address 8;
}
address-allocation round-robin;
mapping-timeout 120;
}
pool DELTA_REAL_IP {
address 185.13.112.248/29;
port {
automatic {
random-allocation;
}
}
address-allocation round-robin;
}
rule AMS {
match-direction input;
term DELTA_REAL_IP {
from {
source-address {
192.168.72.0/24;
}
destination-address {
8.8.8.8/32;
}
}
then {
translated {
source-pool DELTA_REAL_IP;
translation-type {
napt-44;
}
address-pooling paired;
}
}
}
term OFFICE {
from {
source-address {
192.168.72.0/24;
}
application-sets ALG_WITHOUT_EIM_EIF;
}
then {
translated {
source-pool OFFICE;
translation-type {
napt-44;
}
address-pooling paired;
}
}
}
term OFFICE_IEM {
from {
source-address {
192.168.72.0/24;
}
}
then {
translated {
source-pool OFFICE;
translation-type {
napt-44;
}
mapping-type endpoint-independent;
filtering-type {
endpoint-independent;
}
address-pooling paired;
}
}
}
term BRAS {
from {
source-address {
10.141.0.0/16;
10.144.0.0/16;
10.145.0.0/16;
10.146.0.0/16;
10.148.0.0/16;
10.149.0.0/16;
10.150.0.0/16;
10.152.0.0/16;
10.153.0.0/16;
10.154.0.0/16;
10.155.0.0/16;
10.156.0.0/16;
}
application-sets ALG_WITHOUT_EIM_EIF;
}
then {
translated {
source-pool OFFICE;
translation-type {
napt-44;
}
address-pooling paired;
}
}
}
term BRAS_IEM {
from {
source-address {
10.141.0.0/16;
10.144.0.0/16;
10.145.0.0/16;
10.146.0.0/16;
10.148.0.0/16;
10.149.0.0/16;
10.150.0.0/16;
10.152.0.0/16;
10.153.0.0/16;
10.154.0.0/16;
10.155.0.0/16;
10.156.0.0/16;
}
}
then {
translated {
source-pool OFFICE;
translation-type {
napt-44;
}
mapping-type endpoint-independent;
filtering-type {
endpoint-independent;
}
address-pooling paired;
}
}
}
}
}
{master}
admin@M10_MX480>