Adding a DRG NAT Rule

Add a DRG NAT rule to a DRG NAT policy to define how traffic should be translated.

Note the following:

  • If two rules could both match the same packet, the lower priority number wins.
  • If you translate a subnet or host route that's only part of a larger routed network, ensure the translated prefix is also routable.
  • Transit routing scenarios can still be translated if the packet crosses the attachment where the policy is associated.

SNAT-Only Rule

Use SNAT-only when traffic should keep its destination but present a translated source.

    1. On the DRG NAT policies list page, select the DRG NAT policy that you want to work with. If you need help finding the list page or the DRG NAT policy, see Listing DRG NAT Policies.
      The DRG NAT policy's details page opens.
    2. Select Rules.
      The Rules page opens. All rules associated with the DRG NAT policy are listed in a table.
    3. Select Add rule.
      The Add rule panel opens.
    4. Enter the following information:
      • Priority: Enter a unique priority.
      • Original source CIDR: Enter the source CIDR to match.
      • Translated source CIDR: Enter the replacement CIDR of the same prefix length.
      • Original Destination CIDR: Leave empty.
      • Translated Destination CIDR: Leave empty.

      The values you enter can depend on the type of DRG NAT rule you're adding. For more information, see Rule Types.

    5. Select Add rule.
  • Create a JSON file such as add-snat-rules.json:

    [
      {
        "drgNatRulePriority": 10,
        "originalSource": "10.0.0.0/24",
        "translatedSource": "192.168.0.0/24"
      }
    ]

    Use the network drg-nat-rule add command and required parameters to add source NAT rules to a DRG NAT policy:

    oci network drg-nat-rule add --drg-nat-policy-id <policy_ocid> --rules file://add-snat-rules.json

    For a complete list of parameters and values for CLI commands, see the CLI Command Reference.

  • Run the AddDrgNatRules operation to add source NAT rules to a DRG NAT policy.

DNAT-Only Rule

Use DNAT-only when traffic should keep its source but be redirected to a translated destination.

    1. On the DRG NAT policies list page, select the DRG NAT policy that you want to work with. If you need help finding the list page or the DRG NAT policy, see Listing DRG NAT Policies.
      The DRG NAT policy's details page opens.
    2. Select Rules.
      The Rules page opens. All rules associated with the DRG NAT policy are listed in a table.
    3. Select Add rule.
      The Add rule panel opens.
    4. Enter the following information:
      • Priority: Enter a unique priority.
      • Original source CIDR: Leave empty.
      • Translated source CIDR: Leave empty.
      • Original destination CIDR: Enter the destination CIDR to match.
      • Translated destination CIDR: Enter the replacement CIDR of the same prefix length.
    5. Select Add rule.
  • Create a JSON file such as add-dnat-rules.json:

    [
      {
        "drgNatRulePriority": 20,
        "originalDestination": "172.16.10.0/24",
        "translatedDestination": "10.10.10.0/24"
      }
    ]

    Use the oci network drg-nat-rule add command and required parameters to add destination NAT rules to a DRG NAT policy:

    oci network drg-nat-rule add --drg-nat-policy-id <policy_ocid> --rules file://add-dnat-rules.json

    For a complete list of parameters and values for CLI commands, see the CLI Command Reference.

  • Run the AddDrgNatRules operation to add destination NAT rules to a DRG NAT policy.

SNAT-and-DNAT Rule

Use a combined rule when both the source and destination must be translated together.

    1. On the DRG NAT policies list page, select the DRG NAT policy that you want to work with. If you need help finding the list page or the DRG NAT policy, see Listing DRG NAT Policies.
      The DRG NAT policy's details page opens.
    2. Select Rules.
      The Rules page opens. All rules associated with the DRG NAT policy are listed in a table.
    3. Select Add rule.
      The Add rule panel opens.
    4. Enter the following information:
      • Priority: Enter a unique priority.
      • Original source CIDR: Enter the source CIDR to match.
      • Translated source CIDR: Enter the replacement CIDR of the same prefix length.
      • Original Destination CIDR: Enter the destination CIDR to match.
      • Translated Destination CIDR: Enter the replacement CIDR of the same prefix length.

      The settings you configure are determined by the type of rule you're adding. See Rule Types for more information.

    5. Select Add rule.
  • Create a JSON file such as add-snat-dnat-rules.json:

    [
      {
        "drgNatRulePriority": 30,
        "originalSource": "10.0.1.0/24",
        "translatedSource": "192.168.1.0/24",
        "originalDestination": "172.16.20.0/24",
        "translatedDestination": "10.20.20.0/24"
      }
    ]

    Use the oci network drg-nat-rule add command and required parameters to add combined source and destination NAT rules to a DRG NAT policy:

    oci network drg-nat-rule add --drg-nat-policy-id <drg_nat_policy_ocid> --rules file://add-snat-dnat-rules.json [OPTIONS]

    For a complete list of parameters and values for CLI commands, see the CLI Command Reference.

  • Run the AddDrgNatRules operation to add combined source and destination NAT rules to a DRG NAT policy.