---
title: "NAT/Firewall rules"
canonical: "https://docs.aryaka.com/space/KNOW/1511740/NAT%2FFirewall%20rules"
format: markdown
---
The NAT/Firewall page enables you to add a rules-based firewall with advanced network address translation (NAT), port forwarding, port address translation (PAT), source NAT (SNAT), and destination NAT (DNAT) bypass capabilities. This option requires that the site has an ANAP running in edge routed mode or inline routed mode. To add a NAT rule Open the Advanced Settings page from the site's details page if it is not already open, then click the NAT/Firewall tile. The Advanced Settings > NAT/Firewall tab appears. It displays a read-only tabular view of the existing rules associated with the selected site. By default, the rules are displayed with the highest priority rule at the top of the table with each row below it containing the next highest priority rule. The lowest priority rule appears in the last row. Click the  Edit  icon. The same page appears in edit mode, which includes the Add New button. Click  Add New . The NAT (Add) page appears. Enter the following information in the corresponding field: Name—Enter a descriptive name for your NAT rule. This name appears in the NAT rule table. Priority—Enter a positive integer that defines the processing sequence for the rule. The NAT table is searched for a match from the top (first row) to the bottom (last row). The number assigned to the rule in this field positions the rule in the table. Type—Select one of the following rule types: NAT—Maps a server or a subnet on the LAN to an IP address on the M1, M2 interfaces of the ANAP. This rule ensures that inbound and outbound traffic to and from the LAN server or network is allowed. Port Forwarding—Forwards inbound traffic on a public IP and port to a private IP and port of your choice.  PAT—Provides internet access for the site. Bypass SNAT—Bypasses any existing outbound source NAT rules. Bypass DNAT—Bypasses any existing inbound source NAT rules. Protocol—Select one of the following protocols to use as the match criteria for the traffic on which NAT should be performed: TCP UDP ICMP LAN IP—Enter an IP address or select a predefined network object group from the IP Group drop-down list to participate in the NAT configuration. Remote IP—Enter a remote IP address (or subnet) or select a predefined network object group from the IP Group drop-down list to serve as the match criteria that is applied to traffic. This ensures that NAT is only applied to traffic that is going to, or coming from, this remote IP or subnet. LAN Ports—This optional field appears when you click  Advanced  at the top of the Rule (Add) pane. This is a match criteria for the traffic. Setting this field ensures that NAT is only applied to traffic that is to or from this LAN port or selected Port Group. Remote Ports—This optional field appears when you click  Advanced  at the top of the Rule (Add) pane.  This is a match criteria for the traffic. Setting this field ensures that NAT is only applied to traffic that is to or from this remote port or selected Port Group. Egress NAT Interface—This field appears when the NAT rule type is PAT.  The field includes a toggle with the following options: Use Internet Interface IP (default)—Allows for egressing (outbound) traffic to use the IP address on the M1 or M2 interface.  Custom—When selected, displays the M1 IP Address and M2 IP Address drop-down lists. By default, these fields are Disabled. You can select  Use Interface IP  or  Use Custom IP  for M1, M2, or both. If you select Use Custom IP, you must enter an IP address in the field that appears. This is the IP address that participates in the NAT rule when the traffic enters or leaves on the corresponding interface (M1 or M2). External Ports—Specify the port that maps traffic entering or leaving the M1 or M2 interface to the LAN IP and LAN port. Click  OK  in the Rule (Add) pane to validate your entries. This caches the entries, but does  not  save them. They are lost if you reload the page.  Do one of the following: Click  Save Draft  to save a draft of the entries made on this page. Click the  Next  icon or the  Advanced Settings  icon to continue your site configuration on one of other Advanced Settings pages as described in  Configure Advanced Settings . Click  Submit  to send a change request with the entries made on this page to Aryaka support. Related topics Configure Advanced Settings Create internet policies Create WAN Routing and Basic Firewall policies Related videos Add a NAT rule