unsupported address types for NAT(Network Address Translation)
Certain address types are not supported in NAT configurations. The system would report configuration check failures when trying to commit the changes with the unsupported address-books/address-sets are included in NAT
[edit security nat source rule-set src-nat]root@jtac-srx5400-r2005# show from interface fxp0.0;to interface fxp0.0;rule test-ip-prefix { match { source-address-name test-ip-prefix; } then { source-nat { interface; } }}[edit security nat source rule-set src-nat]root@jtac-srx5400-r2005# commit check configuration check succeeds
> Using Addresses and Address Sets in NAT Configurationhttps://www.juniper.net/documentation/us/en/software/junos/security-policies/topics/topic-map/security-address-books-sets.html#concept_qgl_dkw_bybAddress Books and Address Sets | Junos OS | Juniper NetworksPlease refer to below tech docs for newly introduced support for DNS names in NAT configuration: