- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-28-2025 11:45 AM
I have a question about how policies are processed; specifically NAT vs Security Policy.
We have a NAT policy that performs destination NAT to translate all traffic to port 53 to be translated to our corporate DNS servers.
We have a security policy for DNS that permits outbound access to only our corporate DNS servers. All other DNS destinations are blocked.
When looking at the security logs, I see entries showing DNS destinations to other DNS servers (like Google's DNS) getting blocked (which is expected).
I have tested using nslookup on an internal host name using the Google DNS as the server and the response times out and I see it blocked at the firewall.
When does the NAT translation take place?
What should my Security policy look like?
07-29-2025 12:16 AM
Hi @jwill2
You can look into a packet flow diagram to find your answer:
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!