Description

In certain situations, when the Security Director (SD) is not managing NAT policies, it may remove existing NAT policies from the managed devices. This article explains the symptoms, cause, and recommended solution.

Symptoms

  • NAT policies are unexpectedly deleted from devices.

  • This occurs when performing Update Changes from the Security Devices tab in Security Director.

Because NAT policy configuration is not synchronized with the Junos Space database, SD may delete the NAT policies during a change push. This happens when the Security Director is not managing the NAT policies. Additionally, the NAT updates option is enabled by default, contributing to the issue.






When the NAT option is enabled in the Update Changes workflow, the following preview is displayed

##source-nat-rule-set##
delete security nat source rule-set xxx
##destination-nat-rule-set##
delete security nat destination rule-set xxx
##destination-nat-rule-set##
delete security nat destination rule-set xxx



 

Solution

 

The best practice to update any policy changes is to use the Configuration tab instead of the Security Devices tab.

Example: Updating a Standard Policy

  1. Log in to Security Director.

  2. Navigate to the Configuration tab.

  3. Expand Firewall Policy and click on Standard Policies.

  4. Select the policy that requires updates.

  5. Click on the Update tab to push changes to the device.



Note : If you face any issues, please contact JUNIPER JTAC Support for assistance.
 

Modification History

2024-07-25 : Article Created