At the top of the Interface DIP configuration page, you can see for which interface you are configuring a new dynamic IP (DIP) pool. For example, you see:
Interface: ethernet3/2 (IP/Netmask: 209.122.17.1/24)
Important:
Be sure to exclude the following IP addresses from a DIP pool:
—The
WebUI management IP address
—The
interface and gateway IP addresses
—Any
virtual IP (VIP) and mapped IP (MIP) addresses
On the Interface (DIP) List page, click New, and then enter the necessary information
ID: Enter an identification number for the DIP pool. The range is 4–1023.
Note: You can use the ID number that is already showing in the field, which is the next available number sequentially, or enter a different number.
IP Address Range: Enter the starting and ending IP address of the range.
Note: You can add a maximum of three IP address ranges for an IPv4 fixed-port DIP pool. When the first address range is exhausted, the security device attempts to process the NAT request using the second address range. When the second range is exhausted, the security device attempts to process the NAT request using the third address range. Note that the total range of all IP addresses defined in the fixed-port DIP pool must not exceed the permitted address scope of the subnet. The IP address ranges cannot not overlap. To set the DIP type as fixed-port, you must clear the Port Translation check box.
Port Translation: This option is enabled by default. Enable port translation if you want to allow multiple hosts to share the same IP address. If you enable port translation, up to ~64,500 hosts can share a single IP address. Assigned port numbers identifies which session belongs to which host.
IP Shift: Defines a one-to-one mapping from an original source IP address to a translated source IP address for a range of IP addresses starting from ip_addr3. Such a mapping ensures that the device always translates a particular source IP address from within that range to the same translated address within a DIP pool.
From: Enter the original source IP address to translate.
To: Enter an IP address range to which the original source IP address can be translated.
In the same subnet as the interface IP or its secondary IPs: Select this option if you want the DIP pool to be in the same subnet as the IP address of the primary or secondary interface.
Incoming NAT: Select this option to direct the device to perform NAT on sessions initiated by incoming traffic, such as SIP or H.323.
In the same subnet as the extended IP: Select this option if you want the DIP pool in a different subnet from the one containing the interface IP address.
Extended IP/Netmask: This option allows you to graft a second IP address and an accompanying DIP pool onto an interface that is in a different subnet. You can then enable NAT on a per-policy basis and specify the DIP pool built on the extended interface for the translation. Enter the IP address and netmask for the second IP address and accompanying DIP pool.
Click OK to save your changes.