When I confiugre the NAT and associated security policy then I always confuse about the direction of zones. As I understand NAT zones are always determined by ingress interface zone (source zone) and route lookup gives the outoing interface zone (destination zone) but my question is when we confiugre the associated security policy then zones direction would be post-nat address zones or pre-nat address zones?
Solved! Go to Solution.
Hi...The security rule is post-NAT so you should use the zones where the actual client/server lives. Here's a NAT doc for reference:
The way I use to remember which zone to use for NAT is:
- write the security & NAT rule using the zones where the client & server actually live.
- If this is a dest NAT, then use the zone of the actual client as the source & dest zones in the NAT rule only, not security rule. Security rule will stay the same as described in previous step
thanks But I am not able to understand that destination NAT happens before security policy so in security policy, we should use the post-nated address (private address) but we use the original public address?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!