It is recommended to enable the snat-route-change command in security policies where Source-Nat is implemented (common on Internet access and SD-WAN),
because when enabled the routing information is deleted from the table.
When SNAT is not valid for a session, it means that SD-WAN sessions can be 100% stabilized and redirected if an SD-WAN rule is changed without waiting for the session to expire. (for example, by increasing the latency on one of the SD-WAN lines)
With this configuration disabled (by default) after a routing change, sessions created with SNAT will continue to use the same exit interface, provided the previous route is still active or has expired (although the route is no longer optimal)
config system global
set snat-route-change enable
end
Yorumlar
Yorum Gönder