11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 7: Configuring Network Address Translationnetworks behind the DVCP server. Under normal circumstances,you should not make dynamic NAT exceptions for these networks.6 Click the button next to the From box and enter thevalue of the host IP address, network IP address, orhost range. Click OK.7 Click OK to close the Advanced NAT Settings dialogbox.NOTEDynamic NAT exceptions allow the configuration ofexceptions to both forms of dynamic NAT. You will need tomake dynamic NAT exceptions for any 1-to-1 NAT addressthat would otherwise be subject to dynamic NAT.Using Service-Based Dynamic NATUsing service-based dynamic NAT, you can set outgoingdynamic NAT policy on a service-by-service basis. ServicebasedNAT is most frequently used to make exceptions to aglobally applied simple dynamic NAT entry.For example, use service-based NAT on a network withsimple NAT enabled from the trusted to the optional networkwith a Web server on the optional network thatshould not be masqueraded to the actual trusted network.Add a service icon allowing Web access from the trusted tothe optional Web server, and disable NAT. In this configuration,all Web access from the trusted network to the Webserver is made with the true source IP, and all other trafficfrom trusted to optional is masqueraded.You can also use service-based NAT instead of simpledynamic NAT. Rather than applying NAT rules globally toall outgoing packets, you can start from the premise that nomasquerading takes place and then selectively masqueradea few individual services.106 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!