WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide WatchGuard Firebox System 7.0 User Guide

watchguard.com
from watchguard.com More from this publisher
11.07.2015 Views

Chapter 7: Configuring Network Address TranslationAdding simple dynamic NAT entriesUsing built-in host aliases, you can quickly configure theFirebox to masquerade addresses from your trusted andoptional networks. If trusted hosts are already covered bythe default, non-routable ranges, no additional entries areneeded:• From: Trusted• To: ExternalThe default dynamic entries are listed in the previous section.Larger or more sophisticated networks may require additionalentries in the From or To lists of hosts or host aliases.The Firebox applies dynamic NAT rules in the order inwhich they appear in the Dynamic NAT Entries list. Watch-Guard recommends prioritizing entries based on the volumeof traffic that each represents. From the NAT Setupdialog box:1 Click Add.2 Use the From drop-down list to select the origin of theoutgoing packets.For example, use the trusted host alias to globally enable networkaddress translation from the Trusted network. For a definition ofbuilt-in Firebox aliases, see “Using Aliases” on page 162. Formore information on how to add a user-defined host alias, see“Adding an alias” on page 163.104 WatchGuard Firebox System

Using Simple Dynamic NAT3 Use the To drop-down list to select the destination ofoutgoing packets.4 To add either a host or network IP address, click the ...button. Use the drop-down list to select the addresstype. Enter the IP address or range. Network addressesmust be entered in slash notation.When typing IP addresses, type the digits and periods insequence. Do not use the TAB or arrow key to jump past theperiods. For information on entering IP addresses, see “EnteringIP addresses” on page 43.5 Click OK.The new entry appears in the Dynamic NAT Entries list.Reordering simple dynamic NAT entriesTo reorder dynamic NAT entries, select the entry and clickeither Up or Down. There is no method to modify adynamic NAT entry. Instead, use the Remove button toremove existing entries and the Add button to add newentries.Specifying simple dynamic NAT exceptionsYou can set up ranges of addresses in dynamic NAT so thateach address in that range is a part of the NAT policy. Byusing the dynamic NAT exceptions option you can excludecertain addresses from that policy.From Policy Manager:1 Select Setup => NAT.The NAT Setup dialog box appears.2 Click Advanced.The Advanced NAT Settings dialog box appears.3 Click the Dynamic NAT Exceptions tab.4 Click Add.The Add Exception dialog box appears.5 In the From and To boxes, select Trusted, Optional,dvcp_nets, or dvcp_local_nets.The latter two choices are aliases for VPN Manager and appearif your Firebox is configured as a DVCP client. dvcp_nets refersto networks behind the DVCP client and dvcp_local_nets refers toUser Guide 105

Using Simple Dynamic NAT3 Use the To drop-down list to select the destination ofoutgoing packets.4 To add either a host or network IP address, click the ...button. Use the drop-down list to select the addresstype. Enter the IP address or range. Network addressesmust be entered in slash notation.When typing IP addresses, type the digits and periods insequence. Do not use the TAB or arrow key to jump past theperiods. For information on entering IP addresses, see “EnteringIP addresses” on page 43.5 Click OK.The new entry appears in the Dynamic NAT Entries list.Reordering simple dynamic NAT entriesTo reorder dynamic NAT entries, select the entry and clickeither Up or Down. There is no method to modify adynamic NAT entry. Instead, use the Remove button toremove existing entries and the Add button to add newentries.Specifying simple dynamic NAT exceptionsYou can set up ranges of addresses in dynamic NAT so thateach address in that range is a part of the NAT policy. Byusing the dynamic NAT exceptions option you can excludecertain addresses from that policy.From Policy Manager:1 Select Setup => NAT.The NAT Setup dialog box appears.2 Click Advanced.The Advanced NAT Settings dialog box appears.3 Click the Dynamic NAT Exceptions tab.4 Click Add.The Add Exception dialog box appears.5 In the From and To boxes, select Trusted, Optional,dvcp_nets, or dvcp_local_nets.The latter two choices are aliases for VPN Manager and appearif your <strong>Firebox</strong> is configured as a DVCP client. dvcp_nets refersto networks behind the DVCP client and dvcp_local_nets refers to<strong>User</strong> <strong>Guide</strong> 105

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!