Translating the source address of a flow. Azure Firewall does this automatically to its public IP for outbound internet traffic, and NAT gateway supplies SNAT ports for outbound connections.
Also called source network address translation.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SNAT in context, with comparison tables and the common traps.
Terms in this definition
- Flow
The unit of work inside a Lakeflow pipeline that takes data from a source, transforms it and lands it in a destination like a streaming table. Streaming flows either append or update, and
CREATE FLOWlets you declare a flow apart from the table it feeds. - Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- NAT gateway
Gives a subnet managed, outbound-only SNAT through static public IPs and is Microsoft's preferred explicit outbound option. Unsolicited inbound connections are never accepted.
- SNAT ports
Outbound SNAT relies on these ephemeral ports. About 64,000 come with each public frontend IP and are shared among all backend pool members, so adding frontend IPs or a prefix is the only way to get more.
Related terms
- Default VPC
NSX VPC generated automatically once regional networking is completed for a VCF Automation organization, alongside an NSX project, a transit gateway, a default VPC connectivity profile and an SNAT rule.
- ILPIP
An instance-level public IP is attached straight to a VM's NIC on a 1:1 basis with no SNAT. If the subnet has a NAT gateway, new outbound flows use that instead, though inbound traffic still arrives via the ILPIP.
- NAT
Network address translation: an NSX gateway swaps the source (SNAT) or destination (DNAT) address on passing packets, letting, say, privately addressed VMs reach outside networks.
- Outbound rules
With a Standard Load Balancer, these define explicit outbound SNAT so backend pool VMs reach out via the frontend public IPs.
- VPC connectivity profile
Sets out in NSX how VPCs reach beyond their project: which transit gateway, which external IP blocks, and services like SNAT. Any VPC made through vCenter uses the default one.