Managing DRG NAT Rules

Learn how to use DRG NAT rules to define which source and destination CIDRs should be translated when traffic crosses a DRG attachment.

You can perform the following DRG NAT rules tasks:

Rule Construction Guidelines

Note the following:

  • Rules are evaluated by ascending priority value.
  • Only the first matching rule is applied.
  • Priorities must be unique within a policy.
  • A rule can translate source addresses, destination addresses, or both.
  • For stateless 1:1 NAT, the original and translated CIDRs in a pair must be the same size.
  • A rule can match a subset of a larger routed prefix. It doesn't have to align exactly to a VCN CIDR, subnet CIDR, or advertised on-premises prefix.

Rule Types

Here are the DRG NAT rule types:

  • SNAT only: Configure original source and translated source. Use this pattern when the source address must be translated and the destination address must remain unchanged.
  • DNAT only: Configure original destination and translated destination. Use this pattern when the destination address must be translated and the source address must remain unchanged.
  • SNAT and DNAT: Configure both source and destination pairs in the same rule when both sides of the packet must be translated.

Notes

  • Rules don't automatically update routing for translated CIDRs.
  • Rules can be reused through policy reuse, but the attachment still determines where translation is applied.
  • DNS resolution should be handled separately from NAT translation.