Description

This article explains the import issue for NAT policy/pool with the address referred as DNS host/FQDN

Solution

The Security Director does not support the NAT pool with an FQDN address book. While creating NAT pool, it mentioned in the pool address that "Select a NAT pool address. It can be of type host, range, or network only. Click Create to create a new address". So, as per the current SD code, we don't have the option to configure the pool address as a "DNS host". That is the reason, the import is also failing with your SRX configuration. Please find the below screenshot:



However, the use of DNS names in the NAT policy has started being supported in Junos OS from 22.2. Refer: NAT support for DNS (SRX Series, vSRX, and cSRX)


Since it is not supported. The customer needs to go with the ER.

Modification History

2025-03-09 : Article Created