Support Center > Search Results > SecureKnowledge Details
Policy Based Routing rules matching NATed source address do not work
Symptoms
  • Policy Based Routing rules (sk100500) matching NATed source address do not work when routing decision is based on the regular routing table.

  • Rulebase has a PBR rule matching on a translated source address:

    set pbr rule priority X match from TRANSLATED_IP/MASK
Cause
  1. Source translation always takes place on the server side, and cannot be changed to to client side (like destination translation).
  2. The OS routing decision is taking place before the outbound chain. Therefore the PBR rules are being matched against the original source address.
  3. After the routing decision has been made, the packet enters the outbound chain, where it is getting translated.

Solution
Note: To view this solution you need to Sign In .