scm_create_nat_rule
Create NAT rules in Palo Alto Networks Strata Cloud Manager to translate source or destination IP addresses and ports for network traffic routing.
Instructions
Create a NAT rule.
Args: name: Unique name for the NAT rule. folder: Folder to create the rule in. nat_type: NAT type — 'ipv4' (most common), 'nat64', or 'nptv6'. source_zone: List of source zone names. destination_zone: List of destination zone names. source: Source address objects/groups (default ['any']). destination: Destination address objects/groups (default ['any']). service: Service name (default 'any'). source_translation: Dict describing source NAT, e.g. {'dynamic_ip_and_port': {'interface_address': {'interface': 'ethernet1/1'}}}. destination_translation: Dict describing destination NAT (DNAT/port forwarding), e.g. {'translated_address': '10.0.0.5', 'translated_port': 8080}. description: Optional description. tag: Optional list of tag names. disabled: Whether the rule is disabled (default False). tsg_id: Optional TSG ID or named alias. Defaults to SCM_TSG_ID.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | ||
| folder | Yes | ||
| nat_type | Yes | ||
| source_zone | Yes | ||
| destination_zone | Yes | ||
| source | No | ||
| destination | No | ||
| service | No | ||
| source_translation | No | ||
| destination_translation | No | ||
| description | No | ||
| tag | No | ||
| disabled | No | ||
| tsg_id | No |