NAT policy remediation

Policy Analyzer and Optimizer stages NAT remediation changes before it updates the policy. You can stage remediation for individual rules or for all rules in a duplicate-rule observation.

The available actions depend on the NAT rule type:

  • Manual NAT rules: You can delete or disable selected manual rules

  • Auto NAT rules: You can only delete Auto NAT rules, but you cannot disable them.

Note

Back up your policy before applying any remediation. The changes made modify the NAT policy and cannot be automatically reverted.

Before you begin

  • Ensure that NAT policy analysis is complete and that duplicate-rule observations are available.

  • Verify the Policy last analyzed and Policy last modified values for the policy that you want to remediate.

Procedure


Step 1

In Policy Analyzer and Optimizer, select the NAT policy and under Analysis Actions, click View analysis details to open its analysis details.

Step 2

Click Duplicate rules and expand fully shadowed or redundant rules section that contains anomalies.

Step 3

Expand the observation that contains the rules that you want to remediate.

You can select the rules or select the observation to stage all rules in that observation.

NAT rule remediation

Step 4

Click Stage changes.

Step 5

In Select rules to remediate, select the action for each rule type:

NAT rule type

Available action

Manual rules

Delete all selected or Disable all selected

Auto NAT Rules

Delete all selected.

You cannot disable Auto NAT rules.

Step 6

Select Confirm staging. The staged changes are only for review purposes and are not applied yet.

Note

Staged changes are visible to any user who opens the policy in Policy Analyzer and Optimizer. They remain until a user selects Discard or Apply Remediation, or until a new analysis runs after the policy is edited.

Click View details to inspect and review the staged changes. You can click Undo or Discard to revise the staged remediation.

Step 7

Select Apply Remediation.

Step 8

On the Apply NAT duplicate-rule remediation page, verify the policy and the number of rules to modify, and then select Apply remediation.


After you apply the remediation, Policy Analyzer and Optimizer updates the selected NAT rules and automatically starts a new analysis because the previous analysis is stale. While the new analysis runs, the Observations column for the NAT policy shows In progress. After analysis completes, review the refreshed duplicate-rule observations and policy status. If no analyzed anomalies remain, the policy can show a healthy status.