WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide WatchGuard Firebox System 7.0 User Guide

watchguard.com
from watchguard.com More from this publisher
11.07.2015 Views

Chapter 7: Configuring Network Address Translationstatic NAT. Typically, static NAT is used for publicservices that do not require authentication such asWeb sites and email.1-to-1 NATThe Firebox uses private and public IP ranges thatyou specify, rather than the ranges assigned to theFirebox interfaces during configuration.Choosing which type of NAT to perform depends on theunderlying problem being solved, such as those regardingaddress security or preservation of public IP addresses. Formore information on NAT, see the following collection ofFAQs:https://support.watchguard.com/advancedfaqs/nat_main.aspDynamic NATDynamic NAT is the most commonly used form of NAT. Itworks by translating the source IP address of outboundsessions (those originating on the internal side of the Firebox)to the one public IP address of the Firebox. Hosts elsewhereonly see outgoing packets from the Firebox itself.This type of NAT is most commonly used to conserve IPaddresses. It allows multiple computers to access the Internetby sharing one public IP address. Even if the number ofpublic IP addresses is not a concern, dynamic NAT providesextra security for internal hosts that use the Internetby allowing them to use non-routable addresses.The WatchGuard Firebox System implements two forms ofoutgoing dynamic NAT:Simple dynamic NATUsing host aliases or host and network IPaddresses, the Firebox globally applies networkaddress translation to every outgoing packet. Thisis the most commonly used type of NAT.102 WatchGuard Firebox System

Using Simple Dynamic NATService-based dynamic NATEach service is configured individually foroutgoing dynamic NAT.NOTEMachines making incoming requests over a VPN connectionare allowed to access masqueraded hosts by their actualprivate addresses.Using Simple Dynamic NATIn the majority of networks, the preferred security policy isto globally apply network address translation to all outgoingpackets. Simple dynamic NAT provides a quickmethod to set a NAT policy for your entire network. Formore information on this type of NAT, see the followingFAQ:https://support.watchguard.com/advancedfaqs/nat_howdynamicnat.aspEnabling simple dynamic NATThe default configuration of simple dynamic NAT enablesit from all non-routable addresses to the external network.From Policy Manager:1 Select Setup => NAT.The NAT Setup dialog box appears, as shown in the followingfigure.2 Select the checkbox marked Enable Dynamic NAT.The default dynamic entries are:• 192.168.0.0/16 - External• 172.16.0.0/12 - External• 10.0.0.0/8 - ExternalUser Guide 103

Using Simple Dynamic NATService-based dynamic NATEach service is configured individually foroutgoing dynamic NAT.NOTEMachines making incoming requests over a VPN connectionare allowed to access masqueraded hosts by their actualprivate addresses.Using Simple Dynamic NATIn the majority of networks, the preferred security policy isto globally apply network address translation to all outgoingpackets. Simple dynamic NAT provides a quickmethod to set a NAT policy for your entire network. Formore information on this type of NAT, see the followingFAQ:https://support.watchguard.com/advancedfaqs/nat_howdynamicnat.aspEnabling simple dynamic NATThe default configuration of simple dynamic NAT enablesit from all non-routable addresses to the external network.From Policy Manager:1 Select Setup => NAT.The NAT Setup dialog box appears, as shown in the followingfigure.2 Select the checkbox marked Enable Dynamic NAT.The default dynamic entries are:• 192.168.0.0/16 - External• 172.16.0.0/12 - External• 10.0.0.0/8 - External<strong>User</strong> <strong>Guide</strong> 103

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!