Add NAT rules for Cloud Auto-Scaled Firewalls
To prevent asymmetric routing, add NAT rules in the Management Client.
Steps
- Select Configuration.
- Browse to Policies > Engine Policies, then open your Engine Policy for editing.
-
On the IPv4 NAT tab, add the a rule, then define the source, destination, and service:
- Source — ANY
- Destination — $$ DHCP Interface 1.ip Alias element
- Service — Select the service according to the type of traffic that the Secure SD-WAN Engine handles.
- To define source and destination translation, double-click the NAT cell.
-
On the Source Translation tab, configure source NAT.
- From the Translation Type drop-down menu, select Dynamic.
- Next to the IP Address Pool field, click Select.
- Browse to the $$ DHCP Interface 1.ip Alias element, then click Select.
- Deselect Automatic Proxy ARP.
-
On the Destination Translation tab, configure destination NAT.
- Select Translate Destination.
-
Next to the Translated field, click IP Address, then enter the destination IP address in the protected network.
For example, if the destination is a web server in the protected network, enter the private IP address of the web server.
- Deselect Automatic Proxy ARP.
- Click OK.
- Click Save and Install.