Double NAT
Endpoints and Virtual Appliances that are not behind the same Network Address Translation (NAT) address result in the VAs seeing the IP address of the NAT device instead of the endpoint's IP address.
With Secure Access Virtual Appliance deployments, we do not recommend a double NAT environment. A double NAT environment can limit both the ability to create granular rules and endpoint-level reporting in Secure Access. However, you can still create a separate rule for the NAT IP address, which would be useful for Guest Wi-FI situations, where knowing the endpoint IP address may not necessarily be helpful, but having a separate rule for that group of endpoints is important.