In SRX flow-based processing, the first packet of a new session goes through first path processing, where NAT rule lookup, route lookup, security policy evaluation, and session creation occur. Destination NAT is performed before security policy evaluation, so the translated destination address is used when matching the policy. After the session is created, later packets use fast path processing and follow the cached session information, including the NAT translation state created for the session. Therefore, the flow module is involved with NAT behavior in both first path and fast path processing. Option B is incorrect because destination NAT changes destination addresses, not only source addresses. Options C and D are incomplete because NAT lookup and session installation occur during first path, while established NAT translations are applied during fast path.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit