Scenario 1b: DNAT—Packets destined for the vRouter
In this scenario, packets are destined for a process within the vRouter. When firewall rule sets are applied to locally bound packets on an interface, the firewall rules are applied before DNAT (that is, on the translated destination address); refer to the following figure.