11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 7: Configuring Network Address TranslationAdding simple dynamic NAT entriesUsing built-in host aliases, you can quickly configure the<strong>Firebox</strong> to masquerade addresses from your trusted andoptional networks. If trusted hosts are already covered bythe default, non-routable ranges, no additional entries areneeded:• From: Trusted• To: ExternalThe default dynamic entries are listed in the previous section.Larger or more sophisticated networks may require additionalentries in the From or To lists of hosts or host aliases.The <strong>Firebox</strong> applies dynamic NAT rules in the order inwhich they appear in the Dynamic NAT Entries list. Watch-Guard recommends prioritizing entries based on the volumeof traffic that each represents. From the NAT Setupdialog box:1 Click Add.2 Use the From drop-down list to select the origin of theoutgoing packets.For example, use the trusted host alias to globally enable networkaddress translation from the Trusted network. For a definition ofbuilt-in <strong>Firebox</strong> aliases, see “Using Aliases” on page 162. Formore information on how to add a user-defined host alias, see“Adding an alias” on page 163.104 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!