Analyze NAT policies

Network Address Translation (NAT) Policy Analyzer and Optimizer analyzes Cloud-Delivered Firewall Management Center and On-Premises Firewall Management Center NAT policies and categorizes NAT findings into shadowed rules and redundant rules.

NAT Policy Analyzer and Optimizer reports these NAT finding types.

NAT finding

Meaning

How to interpret it

Shadowed NAT rule

A rule that will never evaluate network traffic because another rule that precedes it over shadows this rule.

Review the shadowing rule and the shadowed rules together. A rule is marked shadowed only when the overlap is complete for the compared dimensions.

Redundant NAT rule

A rule can be removed without changing the final NAT behavior because another rule can handle the traffic with the same effective NAT action.

Policy Analyzer and Optimizer checks the translated action for redundancy. Matching traffic criteria alone is not enough when translated source, destination, service, or PAT behavior differs.