Managing DRG NAT Rules
Learn how to use DRG NAT rules to define which source and destination CIDRs should be translated when traffic crosses a DRG attachment.
You can perform the following DRG NAT rules tasks:
Rule Construction Guidelines
Note the following:
- Rules are evaluated by ascending priority value.
- Only the first matching rule is applied.
- Priorities must be unique within a policy.
- A rule can translate source addresses, destination addresses, or both.
- For stateless 1:1 NAT, the original and translated CIDRs in a pair must be the same size.
- A rule can match a subset of a larger routed prefix. It doesn't have to align exactly to a VCN CIDR, subnet CIDR, or advertised on-premises prefix.
Rule Types
Here are the DRG NAT rule types:
- SNAT only: Configure original source and translated source. Use this pattern when the source address must be translated and the destination address must remain unchanged.
- DNAT only: Configure original destination and translated destination. Use this pattern when the destination address must be translated and the source address must remain unchanged.
- SNAT and DNAT: Configure both source and destination pairs in the same rule when both sides of the packet must be translated.
Notes
- Rules don't automatically update routing for translated CIDRs.
- Rules can be reused through policy reuse, but the attachment still determines where translation is applied.
- DNS resolution should be handled separately from NAT translation.