11-15-2024 06:48 AM
Hi. Is it possible to use FQDN in a manual nat rule.
The aim is to permit inside IPs to an outside cloud domain and nat to a specific public IP.
The acl works with a FQDN object containing a URL. The URL is resolved in DNS and traffic flow allowed.
The NAT would look like this:
internal IPs group public IP object (NAT IP) FQDN object FQDN object
nat (any,outside) source dynamic MAIL-RELAY-SOURCE mail.protection.outlook.com-NAT destination static mail.protection.outlook.com mail.protection.outlook.com
When building the NAT in FMC it wont accept the FQDN object in the original destination field. It will accept it in the Translated destination field.
11-15-2024 08:03 AM
AFAIK FQDNs are not supported in NAT rules.
11-15-2024 08:45 AM
https://www.youtube.com/watch?v=ABIuSzUQPwE
try add object instead of using FQDN directly under NAT
11-18-2024 01:26 AM
In the video hes using a host object in the original destination. As my original destination is a cloud based IP it needs to be a FQDN in order to look up the destination IP. The FMC will not even show a fqdn object to select in the original destination field. I tried to add the fqdn object to an object group but the FMC throws an error and wont apply it.
Looks like ill have to do an object group with manual IP entries. Not great in todays cloud world.
11-18-2024 01:45 AM
If this NAT manual 1:1 you can flip the interface in this case the source will be destiantion and hence you can fqdn.
Thanks
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide