Forum Discussion
Brian_Gibson_30
Feb 21, 2015Nimbostratus
Wow. Some great information here! Thanks so much Nitass and Brad.
I went with the KISS approach and implemented a simple mask. Given the relatively small number of users(less than 200) that are on only a relatively few subnets, this approach gave me a pretty simply SNAT approach without having to track the values. If I was working with a larger user base I likely would have needed to do what Nitass proposed, which is consdierably more elaborate than....
when CLIENT_ACCEPTED {
scan [IP::client_addr] %d.%d.%d.%d 0 0 o3 o4
snat "10.73.$o3.$o4"
}
Thanks for all the helpful ideas though.