12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Using Dynamic NATUsing Dynamic NATDynamic NAT is the most frequently used type of NAT. It changes the source IP address of an outgoingconnection to the public IP address of the Firebox®. Outside the Firebox, you see only the IP address ofthe Firebox on outgoing packets.Many computers can connect to the Internet from one public IP address. Dynamic NAT gives more securityfor internal hosts that use the Internet, because it hides the IP addresses of hosts on your network.With Dynamic NAT, all connections must start from behind the Firebox. Malicious hosts cannot startconnections to the computers behind the Firebox when the Firebox is configured for dynamic NAT.In most networks, the recommended security policy is to apply NAT to all outgoing packets. With Fireware®,dynamic NAT is enabled by default in the Network > NAT dialog box. It is also enabled by defaultin each policy you create. You can override the firewall setting for Dynamic NAT in your individual policies.Adding firewall dynamic NAT entriesThe default configuration of dynamic NAT enables dynamic NAT from all private IP addresses to theexternal network. The default entries are:• 192.168.0.0/16 - Any-External• 172.16.0.0/12 - Any-External• 10.0.0.0/8 - Any-ExternalThese three network addresses are the private networks reserved by the Internet Engineering Task Force(IETF) and usually are used for the IP addresses on LANs. To enable dynamic NAT for private IP addressesother than these, you must add an entry for them. The Firebox applies the dynamic NAT rules in thesequence that they appear in the Dynamic NAT Entries list. We recommend that you put the rules in asequence that matches the volume of traffic the rules apply to.1 From Policy Manager, select Network > NAT.The NAT Setup dialog box appears.114 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!