Hello, I would like to replace all my masquerade rules with Source NAT (SNAT). This has already been done for several internal subnets and appears to work fine. We do not use dynamic external IP addressing so I believe there is no need for masquerade. Additionally, I've read that masquerading requires more processing power than SNAT.
I personally prefer an organized group of SNAT/DNAT/FullNAT rules. It seems also that the UTM's interface for masquerade rules is somewhat lacking compared to the NAT rules (for example, you cannot hover over some objects to get their address which is inconvenient).
Please let me know if there is any reason that ANY masquerade rules MUST exist. I do not see a reason, assuming that I recreate every rule as an SNAT. I understand that masquerade acts in a "catch-all" default scenario ... but I believe if I properly understand the network that all scenarios could be explicitly defined in SNAT.
Am I off base here?
Thank you for your reply.
This thread was automatically locked due to age.