Look at packet flow reveals that DST-NAT is done way before firewall filter rules ... meaning that firewall filter rules will see dst-address with already replaced values.
And, to make things complete: SRC-NAT comes after firewall so in that case firewall will see original src-address.
And, to make things complete: SRC-NAT comes after firewall so in that case firewall will see original src-address.
Statistics: Posted by mkx — Sat Jan 13, 2024 11:06 pm