NAT rule sections and comparison behavior

NAT Policy Analyzer and Optimizer follows the high-level NAT evaluation model used by Cisco Secure Firewall NAT policies. NAT rules are evaluated in section order: Manual NAT before Auto NAT, Auto NAT, and Manual NAT after Auto NAT.

The NAT section determines the rule comparisons that can be reported by NAT Policy Analyzer and Optimizer.

NAT section

What it contains

NAT Policy Analyzer and Optimizer comparison behavior

Manual NAT before Auto NAT

Manual or twice NAT rules evaluated before Auto NAT.

Rules in this section can be compared with rules in the same section, Auto NAT, and Manual NAT after Auto NAT.

Auto NAT

Object NAT rules whose device order is determined internally.

Auto NAT rules can participate in comparisons with Manual NAT before or after sections. NAT Policy Analyzer and Optimizer does not report shadowed or redundant rules within the same Auto NAT section.

Manual NAT after Auto NAT

Manual or twice NAT rules evaluated after Auto NAT.

Rules in this section can be compared with rules in the same section and with rules from earlier comparable sections.