# Conditional SNAT

**URL:** <https://community.a10networks.com/t/conditional-snat/150>\
**Category:** System\
**Tags:** snat\
**Created:** [March 25, 2012, 10:43pm UTC](https://community.a10networks.com/t/conditional-snat/150 "2012-03-25T22:43:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mcyork](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@mcyork](https://community.a10networks.com/u/mcyork)\
**Post date:** [March 25, 2012, 10:43pm UTC](https://community.a10networks.com/t/conditional-snat/150/1 "2012-03-25T22:43:15Z")

</div>

I’d like to SNAT only one subnet of source IP addresses and have the remaining (0.0.0.0) IP addresses SLB as normal. Using an ACL I can nat to different pools however I have not found a combination or pool that will SNAT one network and SLB the rest of the traffic.

```auto
Ideas - pointers?

clients ---- AX ---- servers

```

All clients talk to a VIP on the left of the AX. SLB  
Desire servers to also talk to the VIP on the left however need SNAT to hide their own source IP.

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex002/uploads/a10_community/original/1X/bb9f186d33804d3044a0374e589f49fdf3be1328.png) [@system](https://community.a10networks.com/u/system)\
**Post date:** [March 26, 2012, 1:40am UTC](https://community.a10networks.com/t/conditional-snat/150/2 "2012-03-26T01:40:32Z")

</div>

The best way to accomplish this is with a aFlex script similar to the following.

```auto
when CLIENT\_ACCEPTED \{
  if \{ [IP::addr [IP::client\_addr] equals 192.168.1.0/24] \} \{

```

snatpool snatpool\_name

```auto
\}
\}

```

“snatpool\_name” in this example is created through the command line or GUI. “192.168.1.0/24” should be replaced with the client side network you mentioned. The ACLs should be taken into account as well. All other requests besides those originating from 192.168.1.0/24 will be treated without being SNAT’d.

---

<div class="post-metadata">

**Author:** ![mcyork](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@mcyork](https://community.a10networks.com/u/mcyork)\
**Post date:** [March 26, 2012, 7:49am UTC](https://community.a10networks.com/t/conditional-snat/150/3 "2012-03-26T07:49:28Z")

</div>

ok - I will try this approach. The AFlex documentation implies it will not function as mentioned for you need an existing SNAT on the port before you can manipulate the SNAT pools via snatpool keywords. I will explore.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex002/uploads/a10_community/original/1X/bb9f186d33804d3044a0374e589f49fdf3be1328.png) [@system](https://community.a10networks.com/u/system)\
**Post date:** [March 26, 2012, 3:12pm UTC](https://community.a10networks.com/t/conditional-snat/150/4 "2012-03-26T15:12:39Z")

</div>

I’ve tested this and the documentation is correct. You have to have a SNAT pool assigned to the virtual port in order to use the snatpool command.

---

<div class="post-metadata">

**Author:** ![mcyork](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@mcyork](https://community.a10networks.com/u/mcyork)\
**Post date:** [March 26, 2012, 3:38pm UTC](https://community.a10networks.com/t/conditional-snat/150/5 "2012-03-26T15:38:03Z")

</div>

Then I don’t see an answer to my problem yet. Seems like I must SNAT all traffic or none. My goal is to SNAT conditionally as source IP addresses from the clients are important.

---

<div class="post-metadata">

**Author:** ![guy\_a10](https://avatars.discourse-cdn.com/v4/letter/g/e0b2c6/32.png) [@guy\_a10](https://community.a10networks.com/u/guy_a10)\
**Post date:** [March 26, 2012, 4:23pm UTC](https://community.a10networks.com/t/conditional-snat/150/6 "2012-03-26T16:23:36Z")

</div>

You can do this with ACL based SNAT. You don’t configure a source nat pool to the VPORT but only apply an ACL based SNAT policy. All traffic will get load balanced without SNAT. Only the the network(s) you configure in the ACL will be SNAT’d.

```auto
access-list 10 permit 10.1.1.0 0.0.0.255 

ip nat pool SNAT-pool1 10.1.1.222 10.1.1.222 netmask /24  

slb virtual-server VIP-web 10.20.20.200

```

port 80 tcp  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;access-list 10 source-nat-pool SNAT-pool1

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex002/uploads/a10_community/original/1X/bb9f186d33804d3044a0374e589f49fdf3be1328.png) [@system](https://community.a10networks.com/u/system)\
**Post date:** [March 26, 2012, 4:23pm UTC](https://community.a10networks.com/t/conditional-snat/150/7 "2012-03-26T16:23:50Z")

</div>

I think you have two options. Create a conditional SNAT in the virtual server like below.

`access-list 100 permit ip 10.10.10.0 0.0.0.255 any

slb virtual-server testhttp 10.10.10.141 port 80 http name \_10.10.10.141\_HTTP\_80 access-list 100 source-nat-pool SNAT10`

or you can create a static nat for your servers, and enable snat-on-vip option under the virtual server. This will cause the AX to process the NAT before load balancing. This is commonly used to allow servers to hit a VIP that is also pointing to the server network.
