Datto Networking Appliance (DNA): Outbound NAT



This article describes the Outbound NAT feature for the Datto Networking Appliance (DNA).


  • Datto Networking Appliance (DNA)


The Outbound NAT feature allows an operator to configure firewall rules which route traffic through alternate source IP addresses in the private subnets. This feature requires more than one static IP and permits you to specify which external IP address to use for a given host (one IP) or subnet.

To access the Outbound NAT card, log into the DNA web interface, and click Firewall, as shown in Figure 1.

mceclip0.pngFigure 1: Firewall (click to enlarge)

Once on the Firewall page, click the Outbound NAT link. You will see the Outbound NAT management card shown in Figure 2.

Figure 2: Outbound NAT (click to enlarge)

You will need to have at least one WAN Port with a static IP address and at least one additional static address configured to use the Outbound NAT feature. Otherwise, you will see the error message "You must first add Additional IP Addresses in your WAN setup before using outbound NAT" displayed on the configuration card.

To create a new Outbound NAT rule, select the Egress IP address you want the rule to apply to. Click New Rule, and configure the following settings:

  • Enabled: Check the box if you want this rule to be enabled on save. Uncheck the box to create the rule, but not enable it.
  • Name: Specify the name of the rule. Use a name that will remind you what the rule does.
  • Type: Select the source type.
    • If the Type is Host, the source is a valid internal IP address
    • If the Type is Network, the source is a valid internal IP address and netmask in CIDR form (for example
  • Source: Enter the source IP address that you want to route through the selected Egress IP.

Once you have finished configuring the rule, click Save Changes.

Example Use Case

An MSP has three static IP addresses:,, and

LAN traffic to the Internet goes out of the primary / main IP of by default. The local address for the LAN is

On the same LAN, the MSP has an Exchange server that they want to use a different egress IP for.

So they add an egress rule for, with the local address of the server

The MSP also decides that they want another LAN to go out of a third IP.  They add another egress rule for with the address of that LAN :

Was this article helpful?

0 out of 0 found this helpful

You must sign in before voting on this article.

Want to talk about it? Have a feature request?

Head on over to our Datto Community Forum or the Datto Community Online.

For more Business Management resources, see the Datto RMM Online Help and the Autotask PSA Online Help .

Still have questions? Get live help.

Datto Homepage