You can configure IP translation and IP port translation for a DC gateway with a NAT type. For details, refer to the following operations:
Configuring IP Translation
Configuring Local IP Translation
Rules and Restrictions
- The original IP must be within the CIDR range of the VPC.
- The mapped IP cannot be within the CIDR range of the VPC where the DC gateway is located.
- The original IP cannot be repeated, that is, one IP in a VPC can only be mapped to one IP.
- The mapped IP must be unique and cannot be repeated. That is, multiple VPC IP addresses cannot be mapped to the same IP.
- The original destination IP cannot be the broadcast address (255.255.255.255), class D addresses (224.0.0.0-239.255.255.255), and class E addresses (240.0.0.0-255.255.255.254).
- The local IP translation of the DC gateway supports mapping of a maximum of 100 IP addresses, and each IP mapping supports a maximum of 20 ACL rules (if you need to increase the quota, please submit a ticket application).
Directions
- You can log in to the VPC console.
- In the left sidebar, you can click Direct Connect Gateway to open the management page.
- You can click the DC gateway ID whose gateway type is NAT to open the details page.

- On the DC Gateway Details page, you can select the VPC IP Translation tab to configure the VPC local IP translation.
- In the upper left corner of the IP mapping page, you can click Add to add a local IP mapping.
- In the pop-up Add Local IP Mapping dialog box, you can enter the original IP, mapped IP and remarks.

- You can click OK to complete the IP mapping settings.

(Optional) When you add a local IP mapping, an ACL rule is added by default to allow all inbound and outbound traffic to pass through, that is, the local IP translation is effective for all DC tunnels. You can edit the ACL rule of the local IP translation to change the applicable scope of the local IP translation.
Note:
- When the DC gateway is configured with peer IP translation at the same time, the mapped IP of the peer IP translation rather than the original IP shall be filled as the destination IP of the local IP translation ACL rules.
- The local IP translation ACL rule supports the configuration of protocol (TCP or UDP), source port, destination IP, and destination port. If port and IP are not filled in, it means ALL. When ALL is selected for protocol, ALL is selected for port and IP by default.
On the IP mapping page, you can click Edit ACL Rules on the right side of the IP mapping row to enter the ACL rule editing status.

10. At the bottom of the existing ACL rules, you can click Add a New Row. After the ACL rules are added, you can click Submit.
11. (Optional) When you edit ACL rules, you can modify or delete existing ACL rules. After the operation is completed, you can click Save.

12. (Optional) You can also click the Expand icon on the IP mapping page to expand the IP mapping rule, click Modify or Delete on the right side of the rule row, and confirm the operation after it is completed.

13. (Optional) If you need to modify the local IP mapping, you can click Modify IP Mapping on the right side of the IP mapping row on the IP mapping page to modify the original IP, mapped IP, and remarks of the local IP mapping. You can click OK to make the IP mapping take effect.

- (Optional) If you need to delete the local IP mapping, you can click Delete on the right side of the row where the IP mapping is located on the IP mapping page and confirm the operation. After the IP mapping is deleted, the ACL rules under the IP mapping will be deleted.
Configuring Peer IP Translation
Rules and Restrictions
- The mapped IP cannot be within the CIDR range of the VPC where the DC gateway is located.
- The original IP cannot be repeated, that is, one peer IP of the DC can only be mapped to one IP.
- The mapped IP must be unique and cannot be repeated. That is, multiple DC peer IP addresses cannot be mapped to the same IP.
- The original destination IP cannot be the broadcast address (255.255.255.255), class D addresses (224.0.0.0-239.255.255.255), and class E addresses (240.0.0.0-255.255.255.254).
- The peer IP translation of the DC gateway supports mapping of a maximum of 100 IP addresses (if you need to increase the quota, please submit a ticket application).
Directions
- You can log in to the VPC console.
- In the left sidebar, you can click Direct Connect Gateway to open the management page.
- You can click the DC gateway ID whose gateway type is NAT to open the details page.

4. On the DC Gateway Details page, you can select the IDC IP Translation tab to configure the peer IP translation.
5. In the upper left corner of the IP mapping page, you can click Add to add a peer IP mapping.

6. In the pop-up Add Peer IP Mapping dialog box, you can enter the original IP, mapped IP and remarks, and click OK.

7. (Optional) If you need to modify the peer IP mapping, you can click Modify IP Mapping on the right side of the IP mapping row on the IP mapping page to modify the original IP, mapped IP, and remarks of the peer IP mapping. You can click OK to make the peer IP mapping take effect.

8. (Optional) If you need to delete the peer IP mapping, on the IP mapping page, you can click Delete on the right side of the row where the IP mapping is located and confirm the operation.
Configuring IP Port Translation
Configuring Local Source IP Port Translation
Note:
When local IP translation and local source IP port translation conflict, the local IP translation takes precedence.
Rules and Restrictions
- The mapped IP pool cannot be within the CIDR range of the VPC where the DC gateway is located.
- ACL rules of multiple mapped IP pools cannot overlap, otherwise it causes network address translation conflicts.
- IP addresses in multiple mapped IP pools cannot overlap.
- The mapped IP pool only supports single IP or continuous IP addresses, and the /24 IP range of the continuous IP addresses must be consistent, that is, it supports 192.168.0.1-192.168.0.6 but does not support 192.168.0.1-192.168.1.2.
- The mapped IP pool does not include the broadcast address (255.255.255.255), class D addresses (224.0.0.0-239.255.255.255), and class E addresses (240.0.0.0-255.255.255.254).
- The local source IP port translation supports a maximum of 100 mapped IP pools, and each mapped IP pool supports a maximum of 20 ACL rules (if you need to increase the quota, please submit a ticket application).
Directions
- You can log in to the VPC console.
- In the left sidebar, you can click Direct Connect Gateway to open the management page.
- You can click the DC gateway ID whose gateway type is NAT to open the details page.

4. On the DC Gateway Details page, you can select the VPC Source IP Port Translation tab to configure the local source IP port translation.
5. In the upper left corner of the mapped IP pool page, you can click Add to add a mapped IP pool.

6. In the pop-up Add Mapped IP Pool dialog box, you can enter the mapped IP pool (it supports IP or IP range, and the IP range format is A - B) and remarks, and click OK.

The ACL rules for newly added mapped IP pools deny all inbound and outbound traffic. You need to edit the ACL rules to implement network translation.
Note:
- When the DC gateway is configured with peer IP translation at the same time, the mapped IP of the peer IP translation rather than the original IP shall be filled as the destination IP of the local source IP port translation ACL rules.
- The local source IP port translation ACL rule supports the configuration of protocol (TCP or UDP), source IP, source port, destination IP, and destination port.
On the mapped IP pool page, you can click Edit ACL Rules on the right side of the mapped IP pool to enter the ACL rule editing status.
At the bottom of the existing ACL rules, you can click Add a New Row. After the ACL rules are added, you can click Submit.

10. (Optional) When you edit ACL rules, you can modify or delete existing ACL rules. After the operation is completed, you can click Save.
11. (Optional) You can also click the following Expand icon on the mapped IP pool page to expand the mapped IP pool rule, click Modify or Delete on the right side of the rule row, and confirm the operation after it is completed.

12. (Optional) If you need to modify the mapped IP pool, on the mapped IP pool page, you can click Modify mapped IP pool on the right side of the row where the mapped IP pool is located to modify the IP and remarks of the mapped IP pool.

13. (Optional) If you need to delete a mapped IP pool, you can click Delete on the right side of the mapped IP pool row on the mapped IP pool page, and confirm the operation to delete the mapped IP pool. After the mapped IP pool is deleted, the ACL rules associated with the mapped IP pool will be automatically deleted.
Configuring Local Destination IP Port Translation
Rules and Restrictions
- The original IP must be within the CIDR range of the VPC where the DC gateway is located.
- The same IP port in a VPC can be mapped to multiple different IP ports.
- The mapped IP port cannot be within the CIDR range of the VPC.
- The mapped IP ports cannot be repeated, that is, one IP port cannot be mapped to multiple VPC IP ports.
- The original IP addresses and the mapped IP addresses cannot be the broadcast address (255.255.255.255), class D addresses (224.0.0.0-239.255.255.255), and class E addresses (240.0.0.0-255.255.255.254).
- The local destination IP port translation supports the mapping of a maximum of 100 IP ports (if you need to increase the quota, submit a ticket application).
Directions
- You can log in to the VPC console.
- In the left sidebar, you can click Direct Connect Gateway to open the management page.
- You can click the DC gateway ID whose gateway type is NAT to open the details page.

- On the DC Gateway Details page, you can select the VPC Destination IP Port Translation tab to configure the local destination IP port translation.
- In the upper left corner of the IP port mapping page, you can click Add to add a local destination IP port mapping.

- In the pop-up window, you can select the protocol, enter the original IP port, mapped IP port and remarks, and click OK.

(Optional) If you need to modify the local destination IP port mapping, you can click Modify IP Port Mapping on the right side of the row where the IP port mapping is located on the IP port mapping page to modify the mapping relationship and remarks of the IP port mapping.
(Optional) If you need to delete the local destination IP port mapping, you can click Delete on the right side of the row where the IP port mapping is located on the IP port mapping page and confirm the operation to delete the mapping.
Configuration Example
Examples for Configuring Local IP Translation
If the IP A 192.168.0.3 in the VPC is used as the original IP, it is mapped to the IP B 10.100.0.3 through local IP translation, and:
- The original IP of IP A's active access network packet to the DC peer will be automatically modified to
10.100.0.3. - All network packets of
10.100.0.3accessed by the DC peer will automatically be directed to the IP A192.168.0.3.
Examples for Configuring Peer IP Translation
If the IP D 10.0.0.3 of the DC peer is used as the original IP, it is mapped to the IP C 172.16.0.3 through peer IP translation, and:
- The IP D
10.0.0.3actively accesses the original IP of the network packet of the VPC, which will be automatically modified to the IP C172.16.0.3. - All network packets of the IP C
172.16.0.3accessed by the VPC will automatically be directed to the DC peer IP D10.0.0.3.
Examples for Configuring Local Source IP Port Translation
The IP range of VPC C is 172.16.0.0/16. Third-party banks A and B are connected via a DC, where Bank A's peer IP range is 10.0.0.0/28, requesting the connecting IP range to be 192.168.0.0/28; Bank B's peer IP range is 10.1.0.0/28, requesting the connecting IP rage to be 192.168.1.0/28. Then you can configure two local source IP port translations A and B as follows:
| Configuration | Local Source IP Port Translation A | Local Source IP Port Translation B | |
|---|---|---|---|
| Mapped IP Pool | 192.168.0.1 - 192.168.0.15 | 192.168.1.1 - 192.168.1.15 | |
| ACL rule | Protocol | ALL | ALL |
| Source IP | 172.16.0.0/16 | 172.16.0.0/16 | |
| Source Port | — | — | |
| Destination IP | 10.0.0.0/28 | 10.1.0.0/28 | |
| Destination Port | — | — | |
After the configuration is completed, the network requests for active access to banks A and B in VPC C will be converted to random ports of the corresponding mapped IP pool according to the corresponding ACL rules to access the corresponding DC tunnels.
Examples for Configuring Local Destination IP Port Translation
The IP range of VPC C is 172.16.0.0/16. If you only want to open some ports for active access by the DC peer, you can configure the two local destination IP port mappings A and B according to the following scheme:
- Local Destination IP Port Mapping A: original IP port
172.16.0.1:80, and mapped IP port10.0.0.1:80. - Local Destination IP Port Mapping B: original IP port
172.16.0.0:8080, and mapped IP port10.0.0.1:8080.
After the configuration is completed, the DC peer can actively access ports10.0.0.1:80and10.0.0.1:8080, to achieve active access to the two ports172.16.0.1:80and172.16.0.0:8080in the VPC.