Datto Networking Appliance (DNA): Configuring a 1 to Many NAT



This article describes how to configure the 1 to Many NAT feature on your Datto Networking Appliance (DNA).


  • Datto Networking Appliance (DNA)


The Datto Networking Appliance lets you configure port-forwards from multiple IP addresses so that you can accommodate many internal hosts. This allows more port-forwards than IP addresses.

A 1 to Many NAT requires a static IP address. While you can select any WAN port on the device, Datto recommends that you use a secondary port in any situation where your primary WAN port needs to retain a DHCP assignment.


1. To configure a 1 to Many NAT on your DNA, log into the DNA web interface, and click Networks, as shown in Figure 1.

mceclip0.pngFigure 1: Networks (click to enlarge)

2. Once on the Networks page, in the left-hand sidebar, click the Add button next to the Custom DNS option of your selected port. The following examples use WAN Port 2.

3. On the WAN Port card, configure the Static Address values for your environment.

4. Configure the WAN port's DNS settings.

5. Click Save Changes.

You must configure DNS for the WAN port and save the changes before attempting to add any additional public IP addresses.

mceclip0.pngFigure 2: Configuring WAN port settings (click to enlarge)

6. Click the Security tab, followed by 1 to Many NAT.

mceclip1.pngFigure 3: Firewall → 1 to Many NAT (click to enlarge)

7. Click the Ingress IP for each address configured on the port that you want to create rules for. Then, click New Rule.

Figure 4: Ingress IP configuration (click to enlarge)

8. Configure your NAT rules as desired. The options are: 

  • Name: Specify a name for the NAT rule
  • Incoming Port(s): Choose Single or Range from the drop-down, and specify the port range
  • Protocol: Select TCPUDP, or Both 
  • Destination IP: Specify the destination IP to forward the connection to.
  • Port: Specify the port to forward the connection to.

mceclip0.pngFigure 5: NAT rule configuration (click to enlarge)

9. You can create multiple rules per ingress IP, and specify up to 4 ingress IPs per port. When you are finished creating rules, click Save Changes. Your DNA will display a summary of your port configuration, When you enter a port range, that range will also be the destination port range but will show as blank in the UI.

Figure 6: NAT rule configuration summary (click to enlarge)

Was this article helpful?

0 out of 0 found this helpful

You must sign in before voting on this article.

Want to talk about it? Have a feature request?

Head on over to our Datto Community Forum or the Datto Community Online.

For more Business Management resources, see the Datto RMM Online Help and the Autotask PSA Online Help .

Still have questions? Get live help.

Datto Homepage