VMware Networking Community
Marcin4
Enthusiast
Enthusiast

NSX 3.1 DNAT

Hello,

I'm using NSX 3.1

I'm trying to figure out how to create DNAT on T1 with specific destination port ? I dont see any option on wizard. Any solution??

Marcin4_1-1613739521062.png

 

Best Regards
Marcin Gwóźdź
VCP-NV 6, VCIX-DCV 7, VCIX-DTM 7.
linkedin.com/in/marcin-gwóźdź-80b84b122
0 Kudos
5 Replies
CyberNils
Hot Shot
Hot Shot

Haven't used this, but I think you click on Set next to Service to do this.

Cheers.



Nils Kristiansen
https://cybernils.net/
0 Kudos
Marcin4
Enthusiast
Enthusiast

I have tryied that, but didint work.

 

The thing is that I have NSX-T Load Balancer and DNAT with the same IP but what i want to aquaire is:

DNAT with specific port

Load Balancer with specific ports 

 

for example

public IP: 145.150.150.10

local application at 192.168.100.10

 

I need:

DNAT at port 443 ( 145.150.150.10 -> 192.168.100.10)

LB at port 1010, 1050 (145.150.150.10 -> 192.168.100.10)

 

Right now the whole traffic is taken by DNAT rule because I cant implement specyfic destination port for that rule

Best Regards
Marcin Gwóźdź
VCP-NV 6, VCIX-DCV 7, VCIX-DTM 7.
linkedin.com/in/marcin-gwóźdź-80b84b122
0 Kudos
p0wertje
Hot Shot
Hot Shot

Hi,

 

I dont think this is possible. The loadbalance ip is running on the loadbalancer and not on the T1.
What you could do is creating a second vip with the same ip, with another port with a pool containing the server you want to go  to.

Or use an additional ip for the Dnat

Cheers,
p0wertje | VCIX6-NV | JNCIS-ENT | vExpert
Please kudo helpful posts and mark the thread as solved if solved
0 Kudos
mauricioamorim
VMware Employee
VMware Employee

Instead of configuring NAT for port 443 why don't you create another LB VIP with port 443? Can you elaborate more on your use case? From what I understood you have one single server on 192.168.100.10 that you want to be accessed by the public IP of 145.150.150.10. Why not NAT everything or LB everything?

0 Kudos
Marcin4
Enthusiast
Enthusiast

The 443 is load balanaced by another sacnning VM, thats why i need DNAT here

The other ports are for an application workload thatand need to be balanced by NSX-T balancer. 

There are many servers 192.168.100.10, 192.168.100.11, 192.168.100.12.  

my mistake.

DNAT X public IP for Y VM

LB X public IP for Z VM 

Best Regards
Marcin Gwóźdź
VCP-NV 6, VCIX-DCV 7, VCIX-DTM 7.
linkedin.com/in/marcin-gwóźdź-80b84b122
0 Kudos