Forum Discussion

brahim94_11525's avatar
brahim94_11525
Icon for Nimbostratus rankNimbostratus
Jun 02, 2014

AFM: Matching order between AFM rule and NAT

Hi,

 

I have a question on AFM and matching order process between AFM Fw rule and LTM NAT.

 

When I create a new rule, which IP should I use ? Origin or translated IP ?

 

Best regards

 

4 Replies

  • Hi,

     

    Which NAT are you talking about ? If it's SNAT applied on a VS, you don't need to know it when you're on AFM.

     

    SNAT is applied when the packet is leaving out your BIG-IP.

     

  • Hi,

     

    Thank you for the feedback,

     

    OK so for the SNAT when I create rule, I have to use the origin IP. Is it the same thing for destination NAT (create via LTM -> NAT List + Create) ?

     

    Best regards,

     

  • It's the same for the NAT List, you have to use the "original" destination IP.

     

    But be careful, it will be under Global level.