delete_nat_rule
Permanently delete a NAT rule from a Tier-1 gateway. First preview the blast radius to avoid breaking connectivity, then confirm removal.
Instructions
[WRITE] Permanently delete a NAT rule from a Tier-1 gateway's USER NAT section.
Irreversible: traffic matched by the rule stops being translated immediately, which can break inbound (DNAT) or outbound (SNAT) connectivity. Without confirm=True this only previews: it returns blast_radius (the gateway, the rule's action, source/destination match and translation, enabled flag, blockers, unmeasured) and deletes nothing. Show that to the user and get their decision. Do not set confirm=True on your own because the user asked to delete earlier: they have not seen the blast radius yet. confirm=True refuses when the rule could not be read, and a rule_id not on that gateway is an error. Returns {"action": "preview" | "deleted", "blast_radius": ...}, else {"error", "hint", "blast_radius"?}.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | No | NSX Manager target from config (default if omitted). | |
| confirm | No | False (default) returns the blast radius and changes nothing. True applies it. | |
| rule_id | Yes | NAT rule ID to delete, as returned by list_nat_rules. | |
| tier1_id | Yes | Gateway that owns the rule, as returned by list_tier1_gateways. |