Also with this double NAT configuration I'm not getting any translation hits on the source NAT but getting hits on the destination NAT. Can you assist on the source nat?I add port 6004 on the dnat pool and a destination nat policy with application TCP-6004.
Here is the source nat rule. The ip addresses used are just for example.
security {
ike {
respond-bad-spi 1;
}
nat {
source {
pool pool-5 {
address {
10.30.20.10/32 to 10.30.20.10/32;
}
}
pool pool-4 {
address {
10.20.20.7/32 to 10.20.20.7/32;
}
}
rule-set source-nat-1 {
from zone "BLAN";
to zone "ELAN";
rule rule5 {
match {
source-address 10.20.20.1/32;
destination-address 10.20.20.7/32;
}
then {
source-nat {
pool pool-5;
}
}
}
}
rule-set source-nat-2 {
from zone "ELAN";
to zone "BLAN";
rule rule4 {
match {
source-address 10.30.20.1/32;
destination-address 10.30.20.10/32;
}
then {
source-nat {
pool pool-4;
}
}
}
}
}
Source NAT policies
from-zone "BLAN" to "ELAN"
policy 34 {
match {
source-address MI;
destination-address ES;
application TCP/6004;
}
then {
permit;
log {
session-init;
from-zone ELAN to-zone BLAN {
policy 33 {
match {
source-address EA;
destination-address MP;
application TCP/6004;
}
then {
permit;
log {
session-init;
Routes
static {
route 10.20.20.7/32 {
next-hop 10.2.1.1;
preference 20;
}