Learn how to install, configure, and operate Vyatta Network Operating System (Vyatta NOS), which helps to drive our virtual networking and physical platforms portfolio.

Scenario 2a: SNAT—Packets passing through the vRouter

Firewall rules are applied before DNAT. This sequence means that firewall decisions based on source address are made on the translated source address—not the original source address. This order of evaluation is true for both inbound and outbound packets; refer to the following figure.

Note: SNAT firewall rules are applied on original source address.
Figure 1. Pass-through SNAT firewall decisions