11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 7: Configuring Network Address TranslationUsing 1-to-1 NAT1-to-1 NAT uses a global NAT policy that rewrites andredirects packets sent to one range of addresses to a completelydifferent range of addresses. This address conversionworks in both directions. You can configure anynumber of 1-to-1 NAT addresses.A common reason to use 1-to-1 NAT is to map public IPaddresses to internal servers without needing to renumberthose servers. 1-to-1 NAT is also used for VPNs in whichthe remote network’s IP addressing scheme conflicts withthe local scheme. By translating the local network to arange that is not in conflict with the other end, both sidescan communicate. For more information on 1-to-1 NAT, seethe following FAQ:https://support.watchguard.com/advancedfaqs/nat_onetoone.aspEach NAT policy contains four configurable pieces of information:• The interface (External, Trusted, Optional, IPSec)• The public IP address• The internal IP address• The number of hosts to remapThe NAT base plus the range defines the NAT region whilethe real base plus the range defines the hidden or forwardedregion.For instance, the following policy:210.199.6.0–192.168.69.0:255 (NAT base to real baserange)means that all traffic addressed to hosts between210.199.6.0 and 210.199.6.255 is forwarded to the correspondingIP address between 192.168.69.0 and192.168.69.255.110 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!