WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide WatchGuard Firebox System 7.0 User Guide

watchguard.com
from watchguard.com More from this publisher
11.07.2015 Views

Chapter 7: Configuring Network Address TranslationUsing 1-to-1 NAT1-to-1 NAT uses a global NAT policy that rewrites andredirects packets sent to one range of addresses to a completelydifferent range of addresses. This address conversionworks in both directions. You can configure anynumber of 1-to-1 NAT addresses.A common reason to use 1-to-1 NAT is to map public IPaddresses to internal servers without needing to renumberthose servers. 1-to-1 NAT is also used for VPNs in whichthe remote network’s IP addressing scheme conflicts withthe local scheme. By translating the local network to arange that is not in conflict with the other end, both sidescan communicate. For more information on 1-to-1 NAT, seethe following FAQ:https://support.watchguard.com/advancedfaqs/nat_onetoone.aspEach NAT policy contains four configurable pieces of information:• The interface (External, Trusted, Optional, IPSec)• The public IP address• The internal IP address• The number of hosts to remapThe NAT base plus the range defines the NAT region whilethe real base plus the range defines the hidden or forwardedregion.For instance, the following policy:210.199.6.0–192.168.69.0:255 (NAT base to real baserange)means that all traffic addressed to hosts between210.199.6.0 and 210.199.6.255 is forwarded to the correspondingIP address between 192.168.69.0 and192.168.69.255.110 WatchGuard Firebox System

Using 1-to-1 NATA one-to-one mapping exists between each NAT addressand the forwarded (real) IP address: 210.199.6.0 becomes192.168.69.0.From Policy Manager:1 Select Setup => NAT.The NAT Setup dialog box appears.2 Click Advanced.The Advanced NAT Settings dialog box appears.3 Click the 1-to-1 NAT Setup tab.4 Select the checkbox marked Enable 1-1 NAT.5 Click Add.The 1-1 Mapping dialog box appears, as shown in the followingfigure.6 Select the appropriate interface (external, trusted,optional, or IPSec).7 Enter the number of hosts to be translated.8 In the NAT base field, enter the base address for theexposed NAT range.This will generally be the public IP address that will appearoutside the Firebox.9 In the Real base field, enter the base address for thereal IP address range. Click OK.This will generally be the private IP address directly assigned tothe server or client.10 Click the Dynamic NAT Exceptions tab.You must make dynamic NAT exceptions for any internal addressbeing used for 1-to-1 NAT; otherwise, the address will betranslated using dynamic NAT instead of 1-to-1 NAT.11 Click Add.The Add Exception dialog box appears.User Guide 111

Using 1-to-1 NATA one-to-one mapping exists between each NAT addressand the forwarded (real) IP address: 210.199.6.0 becomes192.168.69.0.From Policy Manager:1 Select Setup => NAT.The NAT Setup dialog box appears.2 Click Advanced.The Advanced NAT Settings dialog box appears.3 Click the 1-to-1 NAT Setup tab.4 Select the checkbox marked Enable 1-1 NAT.5 Click Add.The 1-1 Mapping dialog box appears, as shown in the followingfigure.6 Select the appropriate interface (external, trusted,optional, or IPSec).7 Enter the number of hosts to be translated.8 In the NAT base field, enter the base address for theexposed NAT range.This will generally be the public IP address that will appearoutside the <strong>Firebox</strong>.9 In the Real base field, enter the base address for thereal IP address range. Click OK.This will generally be the private IP address directly assigned tothe server or client.10 Click the Dynamic NAT Exceptions tab.You must make dynamic NAT exceptions for any internal addressbeing used for 1-to-1 NAT; otherwise, the address will betranslated using dynamic NAT instead of 1-to-1 NAT.11 Click Add.The Add Exception dialog box appears.<strong>User</strong> <strong>Guide</strong> 111

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!