Associating a NAT Policy with an Attachment
Associate a DRG NAT policy with an attachment to make the policy active for traffic entering and leaving that attachment.
Note
Each DRG attachment can be associated with only one DRG NAT policy at a time.
Each DRG attachment can be associated with only one DRG NAT policy at a time.
- Note
The OCI Networking service rejects NAT on DRG requests for V1 DRGs, loopback attachments, and any DRG with disintermediation, high-throughput mode, or route unification enabled. First, use the oci network drg-attachment update command and required parameters to associate a NAT policy with an attachment:
oci network drg-attachment update --drg-attachment-id <drg_attachment_ocid> --drg-nat-policy-id <drg_nat_policy_ocid> [OPTIONS]For a complete list of parameters and values for CLI commands, see the CLI Command Reference.
Run the UpdateDrgAttachment operation to associate a NAT policy with an attachment.
Validation
After completing your DRG attachment association tasks, validate all the following:
- The translated source or destination CIDRs exist in the correct DRG and VCN route tables where needed.
- On-premises route advertisements include translated prefixes when return traffic depends on them.
- Traffic that doesn't match a rule continues to forward normally.
- DNS still resolves to usable addresses for the translated path.
You can also verify the association by listing the attachments associated with a DRG NAT policy. For more information, see Listing the Attachments Associated with a DRG NAT Policy.