Analyze NAT policies
Network Address Translation (NAT) Policy Analyzer and Optimizer analyzes Cloud-Delivered Firewall Management Center and On-Premises Firewall Management Center NAT policies and categorizes NAT findings into shadowed rules and redundant rules.
NAT Policy Analyzer and Optimizer reports these NAT finding types.
|
NAT finding |
Meaning |
How to interpret it |
|---|---|---|
|
Shadowed NAT rule |
A rule that will never evaluate network traffic because another rule that precedes it over shadows this rule. |
Review the shadowing rule and the shadowed rules together. A rule is marked shadowed only when the overlap is complete for the compared dimensions. |
|
Redundant NAT rule |
A rule can be removed without changing the final NAT behavior because another rule can handle the traffic with the same effective NAT action. |
Policy Analyzer and Optimizer checks the translated action for redundancy. Matching traffic criteria alone is not enough when translated source, destination, service, or PAT behavior differs. |