Network address translation policy analysis
Network Address Translation policy analysis is a security management capability that
-
analyzes NAT policies to find rules that are shadowed or redundant
-
helps identify rules that are not contributing to effective NAT behavior
-
provides understanding of which rule owns the conflict, and
-
enables downloading of NAT analysis reports for review.
NAT Policy Analyzer and Optimizer requirements
NAT Policy Analyzer and Optimizer has these requirements:
-
NAT Policy Analyzer and Optimizer is available only when AIOps is enabled for the tenant and for the selected data source.
-
For On-Premises Firewall Management Center, NAT Policy Analyzer and Optimizer requires Version 7.6 or later.
-
If NAT Policy Analyzer and Optimizer is disabled in AIOps settings, NAT Policy Analyzer and Optimizer operations are blocked for all data sources.
-
When AIOps is enabled for a data source, Policy Analyzer and Optimizer initiates the initial NAT synchronization and analysis for onboarded data sources.
-
NAT Policy Analyzer and Optimizer performs analysis at the management center level, not on a per-device basis.
Note | Disabled NAT rules are excluded from being analyzed by the Policy Analyzer and Optimizer. |