[Nebula]Is it possible to export NAT rules from Nebula?

Zyxel_Cooldia
Zyxel_Cooldia Posts: 1,511  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

Question
Is it possible to export NAT rules from Nebula?

Answer
It is not possible to export NAT rules from Nebula. However, we can obtain the NAT configuration by accessing the device via SSH and using the CLI command "debug sdwan show firewall running-config".

Assume the NAT rule is configured in Nebula.

We can see the NAT rule in device .

Router# debug sdwan show firewall running-config
<rules>
<firewall-name>SN_port_forwarding_1</firewall-name>
<priority>20001</priority>
<rule-activate>true</rule-activate>
<match>
<destination-ip>
<start-ip>192.168.1.33</start-ip>
<end-ip>192.168.1.33</end-ip>
</destination-ip>
<service>
<service-type>service-port</service-type>
<protocols-option>
<l4proto>6</l4proto>
<proto-port>
<start-port-number>9999</start-port-number>
<end-port-number>9999</end-port-number>
</proto-port>
</protocols-option>
<protocols-option>
<l4proto>17</l4proto>
<proto-port>
<start-port-number>9999</start-port-number>
<end-port-number>9999</end-port-number>
</proto-port>
</protocols-option>
</service>
</match>
<action>
<action-mode>allow</action-mode>
<logging>true</logging>
</action>
</rules>