NAT policy analysis
NAT policy analysis is a security optimization feature that
-
analyzes Cloud-Delivered Firewall Management Center and On-Premises Firewall Management Center NAT policies
-
categorizes NAT findings into shadowed rules and redundant rules, and
-
uses Policy Analyzer and Optimizer to optimize network address translation configurations.
NAT finding types
NAT Policy Analyzer and Optimizer reports these NAT finding types.
|
NAT finding |
Meaning |
How to interpret it |
|---|---|---|
|
Shadowed NAT rule |
A rule that will never evaluate network traffic because another rule that precedes it over shadows this rule. |
Review the shadowing rule and the shadowed rules together. A rule is marked shadowed only when the overlap is complete for the compared dimensions. |
|
Redundant NAT rule |
A rule can be removed without changing the final NAT behavior because another rule can handle the traffic with the same effective NAT action. |
Policy Analyzer and Optimizer checks the translated action for redundancy. Matching traffic criteria alone is not enough when translated source, destination, service, or PAT behavior differs. |