Skip to content

Commit 2dd44ff

Browse files
committed
vpp: T7972: Delete nat44 no-forwarding option from CLI
1 parent 155ddbd commit 2dd44ff

File tree

1 file changed

+0
-18
lines changed

1 file changed

+0
-18
lines changed

docs/vpp/configuration/nat/nat44.rst

Lines changed: 0 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -554,24 +554,6 @@ This setting helps prevent memory exhaustion and ensures predictable performance
554554
# Increase session limit for high-capacity deployment
555555
set vpp settings nat44 session-limit 100000
556556
557-
Forwarding Behavior
558-
-------------------
559-
560-
By default, VyOS NAT44 forwards packets that don't match any NAT rules according to the routing table. This behavior can be controlled:
561-
562-
.. cfgcmd:: set vpp settings nat44 no-forwarding
563-
564-
Disable forwarding of packets that don't match existing NAT translations. When enabled, only packets that match static or dynamic NAT rules will be processed; all other traffic will be dropped.
565-
566-
.. important::
567-
568-
This is a significant difference from traditional NAT solutions. By default, VyOS NAT44 allows non-NAT traffic to be forwarded normally. Using ``no-forwarding`` creates a pure NAT-only device that drops any traffic not covered by NAT rules.
569-
570-
**Use cases for no-forwarding:**
571-
572-
* **Pure NAT gateway**: When the router should only handle NAT traffic and drop everything else
573-
* **Security isolation**: Preventing any non-NAT traffic from traversing the device
574-
575557
Worker Assignment
576558
-----------------
577559

0 commit comments

Comments
 (0)