According to the manual and to the Astaro Knowledge Base SNAT shouldn’t work with network groups or a group of hosts.
I did the following with ASL 5.1:
I created two hosts:
192.168.1.201 FTP_Host1
192.168.1.202 FTP_Host2
Created a network group (FTP_Group) consists of:
FTP_Host1
FTP_Host2
Created a SNAT rule (FTP_SNAT) like this:
FTP_Group -> All / FTP WAN (Address) None
Created a Packet Filter rule like this:
Source: FTP_Group Service: FTP Destination: Any Allow
It seems to work! Just these two hosts are able to connect the FTP server in the Internet. Is this a new feature in ASL 5.1? I’m surprised. The Knowledge Base is saying something different.
“Product Version: 5.000 or later
Summary:
It is not possible to use network groups when creating NAT rules such as DNAT or SNAT. For example, if you have a group of Web Servers behind the firewall, you will have to create individual DNAT rules to accommodate them all.
Further Information:
[:S]
This thread was automatically locked due to age.