Associating a NAT Policy with an Attachment

Associate a DRG NAT policy with an attachment to make the policy active for traffic entering and leaving that attachment.

Note

Each DRG attachment can be associated with only one DRG NAT policy at a time.
  • Note

    The OCI Networking service rejects NAT on DRG requests for V1 DRGs, loopback attachments, and any DRG with disintermediation, high-throughput mode, or route unification enabled.
    1. On the DRG NAT policies list page, select the DRG NAT policy that you want to work with. If you need help finding the list page or the DRG NAT policy, see Listing DRG NAT Policies.
      The DRG NAT policy's details page opens.
    2. Select Attachments.
      The Attachments page opens. All DRG attachments associated with the DRG NAT policy are listed in a table.
    3. Select Add attachment.
      The Add attachments page opens. All available DRG attachments are listed in a table.
    4. Select one or more DRG attachments you want to associate with the DRG NAT policy.
      Note

      Review the NAT policy column to determine whether an attachment is already associated with another NAT policy.
    5. Select Add attachments.
  • First, use the oci network drg-attachment update command and required parameters to associate a NAT policy with an attachment:

    oci network drg-attachment update --drg-attachment-id <drg_attachment_ocid> --drg-nat-policy-id <drg_nat_policy_ocid> [OPTIONS]

    For a complete list of parameters and values for CLI commands, see the CLI Command Reference.

  • Run the UpdateDrgAttachment operation to associate a NAT policy with an attachment.

Validation

After completing your DRG attachment association tasks, validate all the following:

  • The translated source or destination CIDRs exist in the correct DRG and VCN route tables where needed.
  • On-premises route advertisements include translated prefixes when return traffic depends on them.
  • Traffic that doesn't match a rule continues to forward normally.
  • DNS still resolves to usable addresses for the translated path.

You can also verify the association by listing the attachments associated with a DRG NAT policy. For more information, see Listing the Attachments Associated with a DRG NAT Policy.