Routing and DNS Considerations

Learn important concepts about using routing and DNS for NAT on DRG.

Routing and DNS design are critical when you use NAT on DRG. Translation changes packet headers, but it doesn't automatically solve end-to-end reachability or name resolution. Ensure that translated prefixes are reachable everywhere they need to be seen, and that DNS returns addresses that match the intended application path.

Routing Considerations

A NAT rule doesn't need to match an entire connected network or an entire advertised route. A rule can translate an entire routed CIDR, a subset of a larger routed CIDR, or a single host route. For example, a VCN subnet might be /24 while the rule translates only a /32 address inside that subnet.

The original network also doesn't need to be directly attached to the DRG. In a hub-and-spoke design, a spoke VCN might connect to a hub VCN through an LPG, and the hub VCN might connect to the DRG through a VCN attachment. Spoke VCN traffic can still be translated when it traverses the hub VCN attachment where the NAT policy is associated, as long as the policy contains a matching rule.

Translated route management is manual. If traffic leaves an attachment with a translated source or destination, every downstream system must know how to return traffic to that translated prefix. Depending on the path, you might need to add static routes to DRG route tables, add routes to VCN route tables, advertise translated prefixes from on-premises equipment, or adjust LPG hub-and-spoke routing so the translated CIDR resolves to the correct next hop.

Without the corresponding routing changes, translation can succeed at the attachment while the translated packet, return packet, or both still fail elsewhere in the path.

DNS Considerations

NAT on DRG doesn't translate DNS queries or DNS responses. DNS might still return original addresses even when an application path must use translated addresses, so name resolution must be handled in the your DNS implementation. If an application path requires translated addressing, DNS records or forwarding behavior might need to be updated separately.