Destination NAT. Inbound packets get a new target address, letting an outside IP map to a workload inside. On NSX this requires an active-standby gateway.
Also called Destination Network Address Translation.
Read more: Broadcom TechDocs
In the Ultra Transcenders books
Each book explains DNAT in context, with comparison tables and the common traps.
Terms in this definition
- Azure NAT Gateway
Gives every resource in a subnet a managed way out to the internet through one or more fixed public IP addresses, while accepting no unsolicited inbound connections. Azure Container Apps can use it only when the environment is a workload profiles one.
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
- Workload
Also called an experience: a Fabric toolset aimed at one job role, e.g. Data Factory, Data Engineering, Data Warehouse, Real-Time Intelligence or Power BI. Each keeps its data in OneLake.
- NSX
Software that handles networking and security across VCF, covering firewalling, load balancing, NAT, VPCs, overlay segments and Tier-0/1 gateways.
Related terms
- Application rule
Azure Firewall rule type that controls outbound HTTP, HTTPS and MSSQL traffic according to the destination FQDN, with full URL filtering requiring Premium. DNAT and network rules are evaluated before it.
- Azure Firewall rule collection
Set of rules of a single type (DNAT, network or application) that share one action and one priority and sit within a rule collection group. Priority only decides order among collections of the same rule type.
- IP Group
Azure Firewall resource at the top level that groups IP addresses and ranges so many rules can share them; DNAT and application rules use it as a source, while network rules can use it as either source or destination.
- NAT
Network address translation: an NSX gateway swaps the source (SNAT) or destination (DNAT) address on passing packets, letting, say, privately addressed VMs reach outside networks.
- Network rule
In Azure Firewall, these rules filter on protocol, port, IP address or service tag, plus FQDN once DNS proxy is on. Evaluation order puts them after DNAT and ahead of application rules.
- Rule collection group
Top-level container in an Azure Firewall policy for rule collections. Priorities order the groups and collections of the same type, yet DNAT rules are always processed before network rules, and network before application rules.
- Rule processing order
Azure Firewall checks traffic in a fixed sequence. If enabled, threat intelligence filtering acts first; DNAT rules follow, then network and then application rules, after which the infrastructure rule collection applies and anything left is denied by default.