12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Using 1-to-1 NAT4 Click OK. Save the change to the Firebox.Using 1-to-1 NATWhen you enable 1-to-1 NAT, the Firebox® changes and routes all incoming and outgoing packets sentfrom one range of addresses to a different range of addresses. You can configure up to 64 different 1-to-1 NAT addresses. This allows you to configure a 1-to-1 NAT rule for a single /26 network, or a total of 64 IPaddresses among all 1-to-1 NAT rule entries. A 1-to-1 NAT rule always has precedence over dynamic NAT.1-to-1 NAT is frequently used when you have a group of internal servers with private IP addresses thatmust be made public. You can use 1-to-1 NAT to map public IP addresses to the internal servers. You donot have to change the IP address of your internal servers. When you have a group of similar servers (forexample, a group of e-mail servers), 1-to-1 NAT is easier to configure than static NAT for the same groupof servers.To understand how to configure 1-to-1 NAT, we give this example:Company ABC has a group of five privately addressed e-mail servers behind the trusted interface oftheir Firebox X Peak. These addresses are:10.1.1.110.1.1.210.1.1.310.1.1.410.1.1.5Company ABC selects five public IP addresses from the same network address as the external interfaceof their Firebox, and creates DNS records for the e-mail servers to resolve to. These addresses are:50.1.1.1116 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!