Configuring the staticdstnat Policy Group
This policy group contains two policy rules:
- SFWR —Acts as an artificial firewall rule that ensures that the SAE activates a basic firewall service for the access before activating a NAT service; the Junos OS requires that a firewall be active before you implement a NAT rule.
- PR—Defines the policy for the static destination NAT service.
The only setting you can modify for this policy group is the precedence setting for the SFWR policy rule. The value for this setting should be higher than the precedence of any other firewall exception. This distinction ensures that the SAE activates the artificial firewall rule first.