- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-28-2016 06:57 AM
Hello Experts
When I confiugre the NAT and associated security policy then I always confuse about the direction of zones. As I understand NAT zones are always determined by ingress interface zone (source zone) and route lookup gives the outoing interface zone (destination zone) but my question is when we confiugre the associated security policy then zones direction would be post-nat address zones or pre-nat address zones?
11-01-2016 07:50 AM - edited 11-01-2016 07:51 AM
Hi...The security rule is post-NAT so you should use the zones where the actual client/server lives. Here's a NAT doc for reference:
The way I use to remember which zone to use for NAT is:
- write the security & NAT rule using the zones where the client & server actually live.
- If this is a dest NAT, then use the zone of the actual client as the source & dest zones in the NAT rule only, not security rule. Security rule will stay the same as described in previous step
10-29-2016 08:23 AM
Hello
Is there any one?
11-01-2016 07:50 AM - edited 11-01-2016 07:51 AM
Hi...The security rule is post-NAT so you should use the zones where the actual client/server lives. Here's a NAT doc for reference:
The way I use to remember which zone to use for NAT is:
- write the security & NAT rule using the zones where the client & server actually live.
- If this is a dest NAT, then use the zone of the actual client as the source & dest zones in the NAT rule only, not security rule. Security rule will stay the same as described in previous step
11-05-2016 11:55 AM - edited 11-05-2016 12:04 PM
thanks But I am not able to understand that destination NAT happens before security policy so in security policy, we should use the post-nated address (private address) but we use the original public address?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!