11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CHAPTER 7Configuring NetworkAddress TranslationNetwork address translation (NAT) protects your networkby hiding its internal structure. It also providesan effective way to conserve public IP addresses whenthe number of addresses is limited.At its most basic level, NAT translates the address of apacket from one value to another. The “type” of NATperformed refers to the method of translation:Dynamic NATAlso called IP masquerading or port addresstranslation. The <strong>Firebox</strong> either globally, or on aservice-by-service basis, applies its public IPaddress to outgoing packets instead of usingthe IP address of the session behind the<strong>Firebox</strong>.Static NATAlso called port forwarding. Static NAT workson a port-to-host basis. Incoming packets fromthe external network destined for a specificpublic address and port are remapped to anaddress and port behind the firewall. Youmust configure each service separately for<strong>User</strong> <strong>Guide</strong> 101

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!