Creating a DRG NAT Policy

Create a DRG NAT policy in Oracle Cloud Infrastructure.

A DRG NAT policy is a reusable container for NAT rules. After you create the policy, you can add source NAT rules, destination NAT rules, or combined source and destination NAT rules, and then associate the policy with one or more supported DRG attachments. Traffic is translated only when it traverses an attachment that is associated with the policy.

See Limits by Service for a list of applicable limits and instructions for requesting a limit increase.

  • On the DRG NAT policies list page, select Create. If you need help finding the list page, see Listing DRG NAT Policies.

    Creating a DRG NAT policy consists of the following pages:

    • 1. Basic information
    • 2. Rules
    • 3. Attachments
    • 4. Review and create

    1: Basic Information

    Enter the following information:

    • Name: A descriptive name for the DRG NAT policy. It doesn't have to be unique, and it can be changed later. Avoid entering confidential information.
    • Create in compartment: The compartment in which you want to create the DRG NAT policy, which could be different from the compartment you're working in.
    • (Optional) Expand and enter information for Tags: If you have permissions to create a resource, then you also have permissions to apply free-form tags to that resource. To apply a defined tag, you must have permissions to use the tag namespace. For more information about tagging, see Resource Tags. If you're not sure whether to apply tags, skip this option or ask an administrator. You can apply tags later.

    Select Next.

    2: Rules

    (Optional) Add the rules for this policy now or add them after the policy has been created. You can add up to a maximum of 15 rules during creation, and more rules later after you create your policy. For more information about DRG NAT policy rules, see Managing DRG NAT Rules.

    Enter the following information:

    • Original source CIDR: The source IPv4 CIDR to match for source NAT. Enter this value when you want the rule to translate the packet's source address.
    • Translated source CIDR: The replacement IPv4 CIDR for the original source CIDR. For stateless 1:1 NAT, this CIDR must be the same size as the original source CIDR.
    • Original Destination CIDR: The destination IPv4 CIDR to match for destination NAT. Enter this value when you want the rule to translate the packet's destination address.
    • Translated Destination CIDR: The replacement IPv4 CIDR for the original destination CIDR. For stateless 1:1 NAT, this CIDR must be the same size as the original destination CIDR.
    • Priority: The evaluation order for the rule within the policy. Lower numbers have higher precedence, and the first matching rule is applied.

    Select Next.

    3: Attachments

    (Optional) Associate an attachment with this policy now, or add it after the policy has been created. Supported DRG attachment types include VCN, remote peering connection, virtual circuit, and IPSec tunnel. To learn more about associating a DRG NAT policy with an attachment, see Associating a NAT Policy with an Attachment.

    From the Search and filter box, select one or more filters and specify the values that you want to use to narrow the list. In general, the filters correspond to the columns shown in the list table, although some filters represent attributes that aren't shown in the table. The Compartment filter is always displayed next to Applied filters.

    Select Next.

    4: Review and create

    Perform a final review of your DRG NAT policy and related configuration. Make any changes necessary and then select Create to start the creation workflow.

    After the creation workflow has started, the Resource creation page opens. Here you can monitor the status of each of the workflow tasks.

  • Use the oci network drg-nat-policy create command and required parameters to create a DRG NAT policy:

    oci network drg-nat-policy create --compartment-id <compartment_ocid> --display-name <drg_nat_policy_name> [OPTIONS]

    For a complete list of parameters and values for CLI commands, see the CLI Command Reference.

  • Run the CreateDrgNatPolicy operation to create a DRG NAT policy.