An understanding of the NAT rule-set evaluation priority is important for configuring NAT. If a packet matches multiple rule-sets, the most specific match takes precedence. The order of precedence is as follows (first destination, then source):
Refer to the 'New Design and Processing' section of TN8 for diagrams of the flow and more information.
Although the title of TN25 refers to ScreenOS users, the examples in the Tech Note are beneficial to non-ScreenOS users, too.
The following commands are helpful for verifying and troubleshooting NAT:
show security nat source summary show security nat source rule show security nat source pool show security nat destination summary show security nat destination pool show security nat destination rule show security nat static rule show security flow session