This article provides a step-by-step guide for configuring destination NAT on an SRX device through the MIST UI.
Follow these steps to properly configure Destination NAT using the MIST UI:
1) Navigate to Organizations > WAN > Networks. Create a network with the name "internet" (The name must be exactly "internet", MIST requires this to push the application policy from WAN to LAN). Set the Subnet IP address to 0.0.0.0/0, as shown below.
2) Under Organizations > WAN > Networks, create the LAN network (if not already created). Configure Destination NAT under this LAN network:
3) Go to Organizations > WAN > Applications. Create an application using the public IP that will be used for Destination NAT.
5) Create an application policy for WAN-to-LAN traffic, as shown below. Please Note, you must include a Traffic steering that points the traffic towards the LAN.
Addendum: Please be advice, as of 04/22/2026, MIST UI only supports DNAT and Static NAT from WAN to LAN, for Overlay or Underlay, If you need to configure DNAT or Static NAT for LAN to LAN or LAN to WAN, These must be configured with SET commands in the "Additional CLI" section of the template or UI.
2025-04-12 : Article Created2026-04-22 : Article modified, removed Previous step 2 as DNAT entries are not to be placed in the INTERNET network, only in the LAN network, as well as added Addendum for LAN to LAN or LAN to WAN DNAT/static NAT