Place the packet onto the internet segment;
the Default-NATPolicySet matches against the Default-InternetRule. This
rule contains the following configuration: Destination
Zone Rule: NAT Zone Internet Match Criteria: any protocol, any prefix, any port Action: Source NAT
In this rule: The
NAT Pool is blank by default, and the system uses the IP Address
bound to the internet interface. The ION device will ARP for IP addresses where the NAT Pool
intersects with the configured interface subnet on the ION device.
Apply
the packet's policy; the source address of 10.10.10.10 overwrites
by the address bound to the Internet Interface (50.50.50.1). The
source port changes to a random port during this operation.
In
this example the original packet: (s) 10.10.10.10:12345: (d) 60.60.60.60:443.
Is rewritten to: (s) 50.50.50.1:54321: (d) 60.60.60.60:443. |