# How can I use a VS IP as a source NAT in WILDCARD VS

**URL:** <https://community.a10networks.com/t/how-can-i-use-a-vs-ip-as-a-source-nat-in-wildcard-vs/822>\
**Category:** ADC - Application Delivery\
**Tags:** snat, nhld, slb-adc, virtual-server-vip\
**Created:** [January 26, 2024, 8:57pm UTC](https://community.a10networks.com/t/how-can-i-use-a-vs-ip-as-a-source-nat-in-wildcard-vs/822 "2024-01-26T20:57:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![anfovar](https://avatars.discourse-cdn.com/v4/letter/a/bc79bd/32.png) [@anfovar](https://community.a10networks.com/u/anfovar)\
**Post date:** [January 26, 2024, 8:57pm UTC](https://community.a10networks.com/t/how-can-i-use-a-vs-ip-as-a-source-nat-in-wildcard-vs/822/1 "2024-01-26T20:57:39Z")

</div>

Hi, guys.  
I’ve observed instances in various clients where an SLB VS is configured alongside NHLD. When an internal client accesses the Internet, the SNAT is typically a pool or auto-NAT, based on our configuration. However, there are scenarios where exceptions are necessary, and an internal client must use the SLB VS IP address. For example:  
SLB VS:  
Name: test  
IP: 8.8.8.8  
Wildcard VS:  
Client A:  
Internal IP: 172.16.200.20  
SNAT: Auto  
Client B:  
Internal IP: 172.16.200.30  
SNAT: 8.8.8.8  
How can I achieve this? I’m trying to do it with an Aflex."

---

<div class="post-metadata">

**Author:** ![dquinn](https://avatars.discourse-cdn.com/v4/letter/d/858c86/32.png) [@dquinn](https://community.a10networks.com/u/dquinn)\
**Post date:** [January 26, 2024, 11:13pm UTC](https://community.a10networks.com/t/how-can-i-use-a-vs-ip-as-a-source-nat-in-wildcard-vs/822/2 "2024-01-26T23:13:59Z")

</div>

If I am understanding the question correctly  
Try associating access-list(s) with nat pool(s) or group(s). Anything that doesn’t match access list will use auto  
access-list 123 8 permit ip host 172.16.200.30 any  
ip nat pool xyz 8.8.8.8 8.8.8.8 netmask /24

port 80 http&nbsp;  
&nbsp;&nbsp;access-list 123 source-nat-pool xyz&nbsp;  
&nbsp;&nbsp;source-nat auto&nbsp;  
&nbsp;&nbsp;service-group sg-1&nbsp;  
&nbsp;&nbsp;sampling-enable all

---

<div class="post-metadata">

**Author:** ![anfovar](https://avatars.discourse-cdn.com/v4/letter/a/bc79bd/32.png) [@anfovar](https://community.a10networks.com/u/anfovar)\
**Post date:** [January 26, 2024, 11:25pm UTC](https://community.a10networks.com/t/how-can-i-use-a-vs-ip-as-a-source-nat-in-wildcard-vs/822/3 "2024-01-26T23:25:31Z")

</div>

Hi dquinn  
The ip 8.8.8.8 is already used as slb virtual server for example let’s say it has a https vport and in wildcard virtual server (0.0.0.0) client B (172.16.200.30) needs to use the ip 8.8.8.8 as snat and Client A (172.16.200.20) will use snat auto

---

<div class="post-metadata">

**Author:** ![mdunn](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@mdunn](https://community.a10networks.com/u/mdunn)\
**Post date:** [January 29, 2024, 4:53pm UTC](https://community.a10networks.com/t/how-can-i-use-a-vs-ip-as-a-source-nat-in-wildcard-vs/822/4 "2024-01-29T16:53:58Z")

</div>

1. The access-list source-nat solution proposed by dquinn should fulfill your requirement. The high-level approach would be:  
configure the access-list to match your internal clients that need VS SNAT IP (client B, etc)
2. configure the source-nat pool with IP address matching your VS IP (8.8.8.8)
3. configure the access-list source-nat under your Wildcard VIP’s port 0 virtual ports.

Clients that match the ACL will receive VS SNAT IP. Clients who miss the ACL will receive SNAT auto IP.

---

<div class="post-metadata">

**Author:** ![anfovar](https://avatars.discourse-cdn.com/v4/letter/a/bc79bd/32.png) [@anfovar](https://community.a10networks.com/u/anfovar)\
**Post date:** [January 31, 2024, 2:46pm UTC](https://community.a10networks.com/t/how-can-i-use-a-vs-ip-as-a-source-nat-in-wildcard-vs/822/5 "2024-01-31T14:46:41Z")

</div>

Thanks Guys  
I did not know that we can use the VIP as pool nat so I finally made it
